The Lanap BotDetect APS.NET CAPTCHA component before 1.5.4.0 stores the UUID and hash for a CAPTCHA in the ViewState of a page, which makes it easier for remote attackers to conduct automated attacks by replaying the ViewState for a known number.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Captcha_asp.net | Lanap_botdetect | * | * |