CVE-2024-38873

An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails to check the requirement of the captcha field in submitted form data, allowing a remote user to bypass the captcha check. This only affects the captcha integration for the ext:form extension.
Configurations

No configuration.

History

14 Mar 2025, 19:15

Type Values Removed Values Added
CWE CWE-284

21 Nov 2024, 09:26

Type Values Removed Values Added
References () https://typo3.org/security/advisory/typo3-ext-sa-2024-004 - () https://typo3.org/security/advisory/typo3-ext-sa-2024-004 -

25 Oct 2024, 19:35

Type Values Removed Values Added
CWE CWE-284

03 Jul 2024, 02:05

Type Values Removed Values Added
CWE CWE-284
Summary
  • (es) Se descubrió un problema en la extensión amigablecaptcha_official (también conocida como Integración de Friendly Captcha) antes de la versión 0.1.4 para TYPO3. La extensión no verifica el requisito del campo captcha en los datos del formulario enviado, lo que permite a un usuario remoto omitir la verificación de captcha. Esto solo afecta la integración de captcha para la extensión ext:form.

21 Jun 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-21 07:15

Updated : 2025-03-14 19:15


NVD link : CVE-2024-38873

Mitre link : CVE-2024-38873

CVE.ORG link : CVE-2024-38873


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control