In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2016/Oct/63 | exploit vdb entry third party advisory |
https://github.com/dotCMS/core/issues/9330 | vendor advisory |
http://www.securityfocus.com/bid/93798 | vdb entry |
https://security.elarlang.eu/cve-2016-8600-dotcms-captcha-bypass-by-reusing-valid-code.html | third party advisory exploit |