Inviting excessive long email addresses to a calendar event makes the server unresponsive

Disclosed: 2023-10-16 13:50:04 By shuvam321 To nextcloud
Medium
Vulnerability Details
## Summary: Due to the absence of a character limit in the email address field when sending emails, requests containing lengthy email addresses causes the server to get delay response, ultimately resulting in a denial of service. ## Steps To Reproduce: 1. As, a low privileged user, go to https://serveraddress/apps/calendar/dayGridMonth/now and create a new calendar. {F2480561} 2. Click on Share link, click on share calendar link via email and intercept the request in burp entering a random email. 3. Send the request to repeater and observe the response time. The server will respond in ~600ms. {F2480573} {F2480610} 4. Now, use the attached payload of 50 MB (email_recipient.txt) in email and send the response. You will get response in about 10000 milllisecond. Larger the email length, longer will be the reponse time. {F2480615} [Note: you may use the following python script and payload attached below. POC attached :) ] ## Impact Denial of service
Actions
View on HackerOne
Report Stats
  • Report ID: 2058337
  • State: Closed
  • Substate: resolved
  • Upvotes: 46
Share this report