Skip to content

Bug Report: Email Spoofing Vulnerability found in assets - [SafeExamBrowser] #20

@priyanshukumar397

Description

@priyanshukumar397

Description

Issue:
Reporting a security vulnerability in [SafeExamBrowser] Asset

Date:
05-10-24

Summary:
Email spoofing vulnerability due to missing DMARC policy on safeexambrowser.org

Description:
The domain safeexambrowser.org lacks a DMARC policy and does not have a Quarantine/Reject policy enabled. This allows unauthorized emails to appear as if they are from safeexambrowser.org increasing the risk of phishing and compromising domain integrity.

Cause:

  • DMARC policy not configured.
  • No Quarantine/Reject policy in place.

Impact:

  • Risk of phishing attacks.
  • Potential damage to domain reputation.

Proof of Concept for the Vulnerability:
image

Recommended Fix:

  • Enable DMARC Policy: For domain mentioned above.
  • Set Policy to Quarantine/Reject: Ensure that emails failing DMARC checks are handled appropriately

Priority:
Medium

Thanks

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions