Skip to content

Bug Report: Email Spoofing Vulnerability found in assets - [SafeExamBrowser] #20

@priyanshukumar397

Description

@priyanshukumar397

Description

Issue:
Reporting a security vulnerability in [SafeExamBrowser] Asset

Date:
05-10-24

Summary:
Email spoofing vulnerability due to missing DMARC policy on safeexambrowser.org

Description:
The domain safeexambrowser.org lacks a DMARC policy and does not have a Quarantine/Reject policy enabled. This allows unauthorized emails to appear as if they are from safeexambrowser.org increasing the risk of phishing and compromising domain integrity.

Cause:

  • DMARC policy not configured.
  • No Quarantine/Reject policy in place.

Impact:

  • Risk of phishing attacks.
  • Potential damage to domain reputation.

Proof of Concept for the Vulnerability:
image

Recommended Fix:

  • Enable DMARC Policy: For domain mentioned above.
  • Set Policy to Quarantine/Reject: Ensure that emails failing DMARC checks are handled appropriately

Priority:
Medium

Thanks

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions