PT-2026-24191 · Oneuptime · Oneuptime
Aryma-F4
·
Published
2026-03-10
·
Updated
2026-03-16
·
CVE-2026-30959
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L |
Name of the Vulnerable Software and Affected Versions
OneUptime (affected versions not specified)
Description
The 'resend-verification-code' endpoint in OneUptime allows an authenticated user to trigger a verification code resend for any
UserWhatsApp record by its itemId. A critical flaw exists because the system does not validate ownership of the UserWhatsApp record before allowing the resend operation, unlike the 'verify' endpoint. This impacts the UserWhatsAppAPI.ts endpoint and the UserWhatsAppService.ts service. An attacker with a valid account and access token can exploit this to repeatedly request verification codes for any user's WhatsApp number, potentially leading to spam, denial-of-service, social engineering attacks, or account lockout. The vulnerable API endpoint is /api/user-whats-app/resend-verification-code, which accepts a JSON payload containing the itemId of the target UserWhatsApp record. The vulnerable parameter is itemId.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authorization
Improper Restriction of Excessive Authentication Attempts
IDOR
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oneuptime