Loading HuntDB...

Email spoofing at weblate.org

W
Weblate
Submitted None
Reported by pyrk2142

Vulnerability Details

Technical details and impact analysis

Good day. I found security bug at weblate.org. Now anybody may send email from weblate.org domain. Now you have SPF policy and DMARC policy, that does not protect anything (because exists insecure domain policy: "p=none" and "sp=none"). Anybody may send email from weblate.org (or subdomain), that are not protected (because SPF does not mean, that email service will do something with spoofed email (for example, Yahoo will add it to inbox)). You may use https://emkei.cz/ to test this bug. For example, I sent email from [email protected] (or [email protected]) to my email and got this message. Why it is dangerous? Attacker may send fake email from your domain and ask user to do somethig. For example, go to site and insert password. User may trust, because email send from normal domain. If you try send email from Facebook main site, Google domain, you will not get message. You may use DMARC Policy (with "p=reject") to prevent sending emails form your domain.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted