Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-1886: Captcha Bypass allows sending unlimited Comments in phpmyfaq

Authentication Bypass by Capture-replay in GitHub repository thorsten/phpmyfaq prior to 3.1.12.

CVE
#git#php#auth

Hello,

I identified a CAPTCHA Bypass after trying many Posts in the Comments Section.

Lets see :)

sent successfully!

let’s see the comments

Comments are available

The Question Form is also vulnerable for Captcha Bypass please check it also too.

Thank you

Impact

Hello,

I identified a CAPTCHA Bypass after trying many Posts in the Comments Section.

Lets see :)

sent successfully!

let’s see the comments

Comments are available

The Question Form is also vulnerable for Captcha Bypass please check it also too.

Thank you

Related news

GHSA-4cr4-x82x-hwm9: thorsten/phpmyfaq vulnerable to authentication bypass

thorsten/phpmyfaq prior to 3.1.12 is vulnerable to authentication bypass by capture-relay that allows unlimited comments to be sent. This has been fixed in 3.1.12.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907