ZeroHour

CVE-2016-8600

PoC ×2
CVSS 3.0
7.5 high
EPSS
2%p77
Published
()
Modified
Description

In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.

Vendors
dotcms
Products
dotcms
Weakness
CWE-254, CWE-264
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.