PT-2024-28249 · Typo3 · Friendlycaptcha Official

Sebastian Müller

·

Published

2024-06-21

·

Updated

2024-10-25

·

CVE-2024-38873

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions friendlycaptcha official extension versions prior to 0.1.4 for TYPO3
Description The issue allows a remote user to bypass the captcha check due to the extension's failure to verify the captcha field in submitted form data. This specifically affects the captcha integration for the ext:form extension.
Recommendations For versions prior to 0.1.4, update to version 0.1.4 or later to resolve the issue. As a temporary workaround, consider disabling the captcha integration for the ext:form extension until the update is applied.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-38873
GHSA-JG62-H7PV-HXGV

Affected Products

Friendlycaptcha Official