TGCaptcha2 version 0.3.0 is vulnerable to a replay attack due to a missing nonce allowing attackers to use a single solved CAPTCHA multiple times.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1316083 | issue tracking vdb entry third party advisory |
https://patrick.uiterwijk.org/2016/03/09/fedora-spam-dwf-2016-89000/ | third party advisory technical description |