60 lines
2.1 KiB
JSON
Raw Normal View History

{
"id": "CVE-2024-38873",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-06-21T07:15:09.110",
"lastModified": "2024-07-03T02:05:21.267",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails to check the requirement of the captcha field in submitted form data, allowing a remote user to bypass the captcha check. This only affects the captcha integration for the ext:form extension."
},
{
"lang": "es",
"value": "Se descubri\u00f3 un problema en la extensi\u00f3n amigablecaptcha_official (tambi\u00e9n conocida como Integraci\u00f3n de Friendly Captcha) antes de la versi\u00f3n 0.1.4 para TYPO3. La extensi\u00f3n no verifica el requisito del campo captcha en los datos del formulario enviado, lo que permite a un usuario remoto omitir la verificaci\u00f3n de captcha. Esto solo afecta la integraci\u00f3n de captcha para la extensi\u00f3n ext:form."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cve@mitre.org",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
}
],
"references": [
{
"url": "https://typo3.org/security/advisory/typo3-ext-sa-2024-004",
"source": "cve@mitre.org"
}
]
}