Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jg62-h7pv-hxgv

Опубликовано: 21 июн. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

FriendlyCaptcha Plugin for TYPO3 Captcha Check Bypass

An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails to check the requirement of the captcha field in submitted form data, allowing a remote user to bypass the captcha check. This only affects the captcha integration for the ext:form extension.

Пакеты

Наименование

studiomitte/friendlycaptcha

composer
Затронутые версииВерсия исправления

< 0.1.4

0.1.4

EPSS

Процентиль: 37%
0.00156
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.3
nvd
больше 1 года назад

An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails to check the requirement of the captcha field in submitted form data, allowing a remote user to bypass the captcha check. This only affects the captcha integration for the ext:form extension.

EPSS

Процентиль: 37%
0.00156
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-284