Skip to content

Bug Report: Email Spoofing Vulnerability found in assets - [SafeExamBrowser] #20

Description

@priyanshukumar397

Description

Issue:
Reporting a security vulnerability in [SafeExamBrowser] Asset

Date:
05-10-24

Summary:
Email spoofing vulnerability due to missing DMARC policy on safeexambrowser.org

Description:
The domain safeexambrowser.org lacks a DMARC policy and does not have a Quarantine/Reject policy enabled. This allows unauthorized emails to appear as if they are from safeexambrowser.org increasing the risk of phishing and compromising domain integrity.

Cause:

  • DMARC policy not configured.
  • No Quarantine/Reject policy in place.

Impact:

  • Risk of phishing attacks.
  • Potential damage to domain reputation.

Proof of Concept for the Vulnerability:
image

Recommended Fix:

  • Enable DMARC Policy: For domain mentioned above.
  • Set Policy to Quarantine/Reject: Ensure that emails failing DMARC checks are handled appropriately

Priority:
Medium

Thanks

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions