Code vulnerable to email flooding

Overview

When creating APIs that send emails programmatically, it's essential to include logic to ensure that messages get sent only if certain conditions apply (for example, CAPTCHAs) to reduce the risk of spamming by bots, sometimes also known as "email flooding".

Business Impact

Decreased operational efficiency, increased potential for human error, delayed time-to-market, and decreased employee satisfaction.

Resources

Common

Incidence

How common is this issue?
6%3%
arrow down2%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
4 months1 month
arrow down65%
shorter
BenchmarkWith Clayton

Frameworks

EasyiconAutomatediconData IntegrityiconData HandlingiconA04:2021 – Insecure Designicon