Email Spoofing on sifchain.finance

Disclosed: 2021-05-11 14:23:23 By ibrahimatix0x01 To sifchain
Low
Vulnerability Details
##Summary: There is an Email Spoofing vulnerability on your domain sifchain.finance which allows an attacker to send an email with your domain name(such as [email protected] and so on). ##Steps To Reproduce: Go to http://emkei.cz Fill "From Email" field to [email protected] or any other sifchain.finance email. Fill the victim's address (your email for test purpose) to "TO" field and fill in other details as you wish. You will receive email from sifchain.finance admin. ## Impact an attacker can send malicious emails to users on your behalf(using your domain(
Actions
View on HackerOne
Report Stats
  • Report ID: 1191209
  • State: Closed
  • Substate: duplicate
  • Upvotes: 6
Share this report