Accepts email addresses without validation
|Reported by:||John Goerzen <jgoerzen@…>||Owned by:||eblot|
trac accepts email addresses without validation several different places — on the New Ticket screen, on the settings screen, etc.
This is bad for several reasons. For starters, it could be abused by spammers. They could put the email address of a victim in the "Your email" box on the New Ticket screen, and submit a ticket to any Trac instance configured to send notifications of new tickets to the submitter.
It could also be used by a miscreant to subscribe an unwitting victim to notifications, as an annoyance.
trac should never send any emails that aren't verified opt-in emails.
Change History (13)
comment:3 Changed 7 years ago by cboos
- Component changed from general to notification
- Milestone set to 1.0
- Owner changed from jonas to eblot
comment:11 Changed 3 years ago by thijstriemstra
- Milestone changed from unscheduled to next-major-0.1X