
Documentation of CVE-2024-50964: critical DMARC policy bypass in DonWeb MX server allowing email spoofing, with low attack complexity and no required privileges.
A critical vulnerability has been identified in Ferozo Webmail v1.1, where the MX (Mail Exchange) server of DonWeb completely disregards configured DMARC (Domain-based Message Authentication, Reporting, and Conformance) policies. Although domains have set DMARC policies to "reject" unauthorized or spoofed emails, DonWeb's mail servers fail to validate these policies, allowing spoofed emails to bypass authentication and reach users' inboxes. This oversight opens the door for attackers to impersonate legitimate domains, significantly increasing the risk of phishing and spoofing attacks.
The oversight in DMARC policy validation on DonWeb's MX server poses a substantial risk to email security, undermining the primary purpose of DMARC as a tool for protecting domains against spoofing and phishing. Addressing this vulnerability is essential to maintain trust and security for users relying on DonWeb’s email infrastructure.
CVE-2024-50964
Reported by [Facundo Fernandez / Security Researcher]