Accepts email addresses without validation
|Reported by:||Owned by:|
|Cc:||jgoerzen@…, Thijs Triemstra|
trac accepts email addresses without validation several different places — on the New Ticket screen, on the settings screen, etc.
This is bad for several reasons. For starters, it could be abused by spammers. They could put the email address of a victim in the "Your email" box on the New Ticket screen, and submit a ticket to any Trac instance configured to send notifications of new tickets to the submitter.
It could also be used by a miscreant to subscribe an unwitting victim to notifications, as an annoyance.
trac should never send any emails that aren't verified opt-in emails.
Change History (14)
comment:3 Changed 11 years ago by
|Component:||general → notification|