Skip to content

Bypassing Captcha on Loginpage

Moderate
Abraxas-Bot published GHSA-r8hq-vwpm-rffc Feb 8, 2024

Package

VOTING IAM (Abraxas Apps Platform)

Affected versions

< v1.29.1

Patched versions

v1.29.1

Description

Short Description

Bypassing Captcha on Loginpage

Reporting Date

  1. November 2023

Details

If there are too many incorrect login attempts, a Captcha puzzle is demanded. This request could be bypassed in the process after removing some querystring parameters within the authentication flow.

Impact

Low

References

  • Bug Bounty ID: deface-AUDIENCE (Private)
  • Internal ID: SEC-1440

❤ Thanks to

Simon Reinhart for reporting the vulnerability.

Severity

Moderate
4.3
/ 10

CVSS base metrics

Attack vector
Adjacent
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVE ID

No known CVE

Weaknesses