PT-2017-18694 · Allen · Allen Disk

Ghost

·

Published

2017-05-19

·

Updated

2020-03-02

·

CVE-2017-9090

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Allen Disk version 1.6
Description The issue allows bypassing the CAPTCHA protection by submitting an empty captcha value in the POST request. This is due to the lack of proper validation of the $ SESSION['captcha']['code'] variable in the reg.php file.
Recommendations For Allen Disk version 1.6, consider adding a check to ensure that the $ SESSION['captcha']['code'] is properly set and validated before allowing registration. As a temporary workaround, consider implementing additional validation for the $ POST['captcha'] variable to prevent empty submissions.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9090

Affected Products

Allen Disk