simple-php-captcha before commit 9d65a945029c7be7bb6bc893759e74c5636be694 allows remote attackers to automatically generate the captcha response by running the same code on the client-side.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/claviska/simple-php-captcha/issues/16 | issue tracking vendor advisory |
http://www.openwall.com/lists/oss-security/2015/08/17/7 | third party advisory mailing list |
https://github.com/claviska/simple-php-captcha/commit/9d65a945029c7be7bb6bc893759e74c5636be694 | patch vendor advisory |