CVE-2024-38873
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails to check the requirement of the captcha field in submitted form data, allowing a remote user to bypass the captcha check. This only affects the captcha integration for the ext:form extension.
Se descubrió un problema en la extensión amigablecaptcha_official (también conocida como Integración de Friendly Captcha) antes de la versión 0.1.4 para TYPO3. La extensión no verifica el requisito del campo captcha en los datos del formulario enviado, lo que permite a un usuario remoto omitir la verificación de captcha. Esto solo afecta la integración de captcha para la extensión ext:form.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-06-21 CVE Reserved
- 2024-06-21 CVE Published
- 2025-03-14 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://typo3.org/security/advisory/typo3-ext-sa-2024-004 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Typo3 Search vendor "Typo3" | Friendlycaptcha Official Search vendor "Typo3" for product "Friendlycaptcha Official" | * | - |
Affected
|