PT-2023-27786 · Typo3+1 · Typo3+1

Devid Messner

·

Published

2023-08-22

·

Updated

2023-08-28

·

CVE-2023-41100

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions hCaptcha for EXT:form extension versions prior to 2.1.2 for TYPO3
Description An issue was discovered in the hcaptcha extension, where it fails to check that the required captcha field is submitted in the form data, allowing a remote user to bypass the CAPTCHA check.
Recommendations For versions prior to 2.1.2, update to version 2.1.2 or later to resolve the issue. As a temporary workaround, consider implementing additional validation checks on form submissions to verify the presence of the required captcha field.

Exploit

Fix

Related Identifiers

CVE-2023-41100
GHSA-93WX-J2QV-49FG

Affected Products

Typo3
Hcaptcha