Email Spoofing on sifchain.finance
Low
Vulnerability Details
##Summary:
There is an Email Spoofing vulnerability on your domain sifchain.finance which allows an attacker to send an email with your domain name(such as [email protected] and so on).
##Steps To Reproduce:
Go to http://emkei.cz
Fill "From Email" field to [email protected] or any other sifchain.finance email.
Fill the victim's address (your email for test purpose) to "TO" field and fill in other details as you wish. You will receive email from sifchain.finance admin.
## Impact
an attacker can send malicious emails to users on your behalf(using your domain(
Actions
View on HackerOneReport Stats
- Report ID: 1191209
- State: Closed
- Substate: duplicate
- Upvotes: 6