---
id: CVE-2026-107830
title: >-
  Jivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on
  the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction,
  allowing unlimited SMS sending
summary: >-
  Jivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on
  the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction,
  allowing unlimited SMS sending. Attackers can load newAccount.jsp to set
  session attri…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-799
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:30.797'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107830'
references:
  - url: 'https://github.com/banq/jivejdon'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/account/newAccount.jsp#L24-L29
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/account/SmsQQAction.java#L23-L79
    label: disclosure@vulncheck.com
  - url: 'https://github.com/banq/jivejdon/issues/28'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/jivejdon-through-commit-ee67a65e-missing-rate-limiting-via-account-smsvraction-sms-endpoint
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-08T23:16:47.393Z'
---

## Overview

Jivejdon from commit e0306088 through commit ee67a65e lacks rate limiting on the unauthenticated /account/smsVRAction endpoint handled by SmsQQAction, allowing unlimited SMS sending. Attackers can load newAccount.jsp to set session attributes, then repeatedly call the endpoint to harass arbitrary phone numbers and exhaust the operator's Tencent Cloud SMS balance.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
