CVE-2016-8600

In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:dotcms:dotcms:3.2.1:*:*:*:*:*:*:*

Information

Published : 2016-10-28 08:59

Updated : 2016-11-28 12:40


NVD link : CVE-2016-8600

Mitre link : CVE-2016-8600


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

CWE-254

7PK - Security Features

Advertisement

dedicated server usa

Products Affected

dotcms

  • dotcms