ZeroHour

CVE-2023-45292

PoC
CVSS 3.1
5.3 medium
EPSS
<1%p22
Published
()
Modified
Description

When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the first parameter is a non-existent id, the second parameter is an empty string, and the third parameter is true, the function will always consider the Captcha to be correct.

Vendors
mojotv
Products
base64captcha
Weakness
CWE-345
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.