Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-44821

Опубликовано: 04 сент. 2024
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the captcha value after a failed validation attempt. As a result, an attacker can exploit this flaw by repeatedly submitting the same incorrect captcha response, allowing them to capture the correct captcha value through error messages.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zzcms:zzcms:*:*:*:*:*:*:*:*
Версия до 2023 (включая)

EPSS

Процентиль: 38%
0.00162
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.3
github
больше 1 года назад

ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the captcha value after a failed validation attempt. As a result, an attacker can exploit this flaw by repeatedly submitting the same incorrect captcha response, allowing them to capture the correct captcha value through error messages.

EPSS

Процентиль: 38%
0.00162
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-287