Jeśli funkcjonalność anti spam-captcha w PluXml w wersji 5.8.22 i wcześniejszych jest włączona, challenge captcha generowany jest w formacie, który można automatycznie rozpoznać dla artykułów, umożliwiając skryptom zautomatyzowanym trywialnym obejście tego mechanizmu i publikację spamowych komentarzy. Szczegóły challenge captcha są ujawniane w treści dokumentu artykułów z włączoną funkcjonalnością komentarzy i anti spam-captcha, w tym „capcha-letter", „capcha-word" i „capcha-token", które mogą być wykorzystane do konstruowania ważnego żądania post w celu publikacji komentarza. W rezultacie atakujący mogą zalewać artykuły zautomatyzowanymi spamowymi komentarzami, szczególnie jeśli brak dodatkowych ochrony na poziomie web.
▸ Pokaż oryginał (EN)
If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that can be automatically recognized for articles, such that an automated script is able to solve this anti-spam mechanism trivially and publish spam comments. The details of captcha challenge are exposed within document body of articles with comments & anti spam-captcha functionalities enabled, including "capcha-letter", "capcha-word" and "capcha-token" which can be used to construct a valid post request to publish a comment. As such, attackers can flood articles with automated spam comments, especially if there are no other web defenses available.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NPluxml
APPPluxml≤ 5.8.22
Powiązane podatności
PluXml 5.7 — zdalne wykonanie kodu PHP przez modyfikację pliku konfiguracyjnego
PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages f...
Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into s...
Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to includ...
Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload a...