The email API to test email-server settings is unlimited and can be used as a email bomb
Medium
Vulnerability Details
**Description:**
The email-server settings test function in `https://demo.nextcloud.com/xxx/settings/admin/additional` is unlimited and can be used as a email bomb.
And the test email API is `https://demo.nextcloud.com/xxx/settings/admin/mailtest`
**Reproduce steps:**
1.Go to `https://demo.nextcloud.com/xxx/settings/personal` ,set your personal address to a email address which you want to attack .see screenshot(1)
2.Then go to `https://demo.nextcloud.com/xxx/settings/admin/additional`,`send test mail` ,then above email address will receive an test email.
3.So I can use chrome console network panel to `replay XHR` continuously,then my email box receive many email.see screenshot(2)
Actions
View on HackerOneReport Stats
- Report ID: 222660
- State: Closed
- Substate: informative
- Upvotes: 2