CVE-2016-8600
HIGH 7.5EPSS 1.8%
In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.
- CVSS v3.0
- 7.5 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N - EPSS
- 1.75% chance of exploitation in the next 30 days, 76th percentile
- Published
- 2016-10-28
- Updated
- 2024-08-06
Proof-of-concept exploits (2)
- http://seclists.org/fulldisclosure/2016/Oct/63
- https://security.elarlang.eu/cve-2016-8600-dotcms-captcha-bypass-by-reusing-valid-code.ht…