Request to route quran.com/sunnah.com security vulnerability reports
Category: Questions & membership Priority: P2 Severity: n/a Area: security Reports: 1 Status: Open
Summary
A user first wrote in to report an Android UI transparency bug in the Qaf app, then — having heard Abdellatif previously worked at quran.com — pivoted to say he had found several security vulnerabilities across the quran.com / sunnah.com properties and could not get a response from that team, and asked Abdellatif to share a contact there. The reported issues are concrete and serious (publicly exposed phpinfo() leaking internal IP and stack, an exposed phpMyAdmin behind only Basic Auth, an unauthenticated Jenkins GitHub webhook, an exposed Docker Registry, and an OTP endpoint with no rate limiting). This is not a Qaf product defect, but it is a genuine security disclosure that deserves routing to the right people. Abdellatif suggested opening a GitHub issue and joining their Discord; the reporter said he later reached a team member (possibly "Osama Sayed") but was unsure all issues were fixed.
What users say
scnz scnz141@gmail.com
- Date: 2026-08-06 (00:38 +03:00)
- Language: English
- Thread:
19fd3d3dfcbea094 - Replied by Abdellatif: Yes (suggested GitHub issue + Discord admins)
Says he found security vulnerabilities on quran.com/sunnah.com properties, tried to contact that team without a response, and — knowing Abdellatif worked at quran.com — asks him to share a contact. He lists several specific findings.
Brother sorry to say this but i heard you worked at quran.com and i found some security vulnerabilities on their site and i tried to contact them but didn't get any respond if you have any contact with them please share
On follow-up about whether the issues were resolved:
I contacted one of their team member i think his name is osama sayed But i am not sure they have fixed all the issues
Few days before i was able to run scripts that generated request volume equal to roughly 30% of the sites total traffic without being throttled or blocked using just my phone
Abdellatif's reply:
Oh, these are pretty important. Have you tried creating an issue on their github? Would also recommend that you join their discord and find the admins
Details / repro
Reported vulnerabilities (verbatim from the reporter), for the quran.com / sunnah.com properties — NOT Qaf:
admin.sunnah.com/test.php—phpinfo()publicly accessible; leaks internal VPC IP (172.31.22.165), OS version (Ubuntu on AWS), PHP 7.4.3, and MySQL configuration.admin.sunnah.com/phpmyadmin/— phpMyAdmin exposed with only Basic Auth; combined with the phpinfo leak, "a direct path to your database."build.quran.com— Jenkins server (v2.528.3) with an unauthenticated GitHub webhook at/github-webhook/; 10 forged push events all accepted (HTTP 200); no webhook secret configured.- Port 5000 on
138.201.255.181— Docker Registry V2 API exposed to the internet. quranreflect.com— OTP verification endpoint with zero rate limiting; 30 consecutive wrong codes were never blocked.- Also claims he could generate request volume ~30% of the site's total traffic from just his phone without being throttled.
- Note: the same thread opened with an unrelated Qaf issue — Android UI transparency bug (tracked separately); Abdellatif suggested using the website
https://qaf.aimeanwhile.
Threads
19fd3d3dfcbea094— Asks for a quran.com/sunnah.com security contact after unanswered disclosures (thread also contains an Android UI transparency bug report)