PT-2026-82371 · Unknown · Captcha Protected Page
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CAPTCHA Protected Page versions 0.0.0 through 1.0.2
Description
An authentication bypass exists in the CAPTCHA Protected Page module, which allows site administrators to require CAPTCHA confirmation on specific pages. The module fails to sufficiently validate its CAPTCHA verification cookies, enabling an unauthenticated user or automated bot to forge the cookie and bypass the verification process entirely.
Recommendations
Update CAPTCHA Protected Page to a version newer than 1.0.2.
Exploit
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Captcha Protected Page