When sending email reports, deduplicate the list of emails addresses to only send the report once per email #14474
Labels
c: Security
For issues that make Matomo more secure. Please report issues through HackerOne and not in Github.
Milestone
-> Goal of this issue is to make sure we only send email reports once to a given email address.
Initial security report
When creating/editing an email report, if you enter the same email address multiple times, like 100 or 1000 times in the field "Send report to", the email reports are sent 100 or 1000 times. This could create problems where the Matomo server sending emails is marked as spam. This could affect Cloud customers if some security tester is sending hundreds of email reports (they are not allowed it as per our bug bounty rules, but some who don't read still do it anyway...).
Suggested steps
The text was updated successfully, but these errors were encountered: