SafeExamBrowser / SafeExamBrowser-Website

Apache License 2.0
7 stars 8 forks source link

Bug Report: Email Spoofing Vulnerability found in assets - [SafeExamBrowser] #20

Open priyanshukumar397 opened 1 month ago

priyanshukumar397 commented 1 month ago

Description

Issue: Reporting a security vulnerability in [SafeExamBrowser] Asset

Date: 05-10-24

Summary: Email spoofing vulnerability due to missing DMARC policy on safeexambrowser.org

Description: The domain safeexambrowser.org lacks a DMARC policy and does not have a Quarantine/Reject policy enabled. This allows unauthorized emails to appear as if they are from safeexambrowser.org increasing the risk of phishing and compromising domain integrity.

Cause:

Impact:

Proof of Concept for the Vulnerability: image

Recommended Fix:

Priority: Medium

Thanks

priyanshukumar397 commented 1 month ago

image

priyanshukumar397 commented 1 month ago

Any updates yet?

danschlet commented 1 month ago

No, we don't have dedicated staff to deal with website issues and have very much to do with issues in the software itself. We will look into this as time permits.

priyanshukumar397 commented 1 month ago

Thanks for your response @danschlet sir, however, kindly confirm if you accept this as a valid bug for a fix.

Also, if you need more folks to join SEB, kindly let me know if I can join the team for testing part including other assets of SEB including itself, as currently I am working on various browser bypasses for various assessments and checks, would be happy to join.

priyanshukumar397 commented 1 month ago

any updates on this request?

Thanks for your response @danschlet sir, however, kindly confirm if you accept this as a valid bug for a fix.

Also, if you need more folks to join SEB, kindly let me know if I can join the team for testing part including other assets of SEB including itself, as currently I am working on various browser bypasses for various assessments and checks, would be happy to join.