CVE Vulnerabilities

CVE-2016-8600

Published: Oct 28, 2016 | Modified: Nov 28, 2016
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.

Affected Software

Name Vendor Start Version End Version
Dotcms Dotcms 3.2.1 (including) 3.2.1 (including)

References