CVE-2026-107830: Jivejdon through commit ee67a65e Missing Rate Limiting via /account/smsVRAction SMS Endpoint
Jivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction, allowing unlimited SMS sending. Attackers can load newAccount.jsp to set session attributes, then repeatedly call the endpoint to harass arbitrary phone numbers and exhaust the operator's Tencent Cloud SMS balance.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
No authentication or user interaction is required. An attacker can first load newAccount.jsp to establish the needed session attributes, then repeatedly invoke /account/smsVRAction.
Who is exposed to abuse?
Deployments running Jivejdon from commit e0306088 through commit ee67a65e are affected. The endpoint can be used to send SMS messages to arbitrary phone numbers, exposing both recipients to harassment and the operator to Tencent Cloud SMS balance exhaustion.
Is the affected endpoint exposed by default?
The data identifies /account/smsVRAction as an unauthenticated endpoint, but does not state whether it is reachable in every default deployment. Exposure depends on whether the application's account registration functionality is reachable to untrusted network users.
How can I check for attempted exploitation?
Review application and web access logs for repeated requests to /account/smsVRAction, particularly when preceded by requests for newAccount.jsp. Also investigate unexpected Tencent Cloud SMS usage or SMS sends to numerous or repeatedly targeted phone numbers.