CVE-2023-45292
11.12.2023, 22:15
When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the first parameter is a non-existent id, the second parameter is an empty string, and the third parameter is true, the function will always consider the Captcha to be correct.Enginsight
Vendor | Product | Version |
---|---|---|
mojotv | base64captcha | 𝑥 < 1.3.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References