Captcha verification bypass in github.com/mojocn/base64Captcha
CVE-2023-45292
5.3MEDIUM
Key Information:
- Vendor
- CVE Published:
- 11 December 2023
What is CVE-2023-45292?
When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the first parameter is a non-existent id, the second parameter is an empty string, and the third parameter is true, the function will always consider the Captcha to be correct.
Affected Version(s)
github.com/mojocn/base64Captcha 0 < 1.3.6