MEDIUM🇬🇧 English

CVE-2025-70129

CVSS 5.3v3.1pub. 2026-03-10upd. 2026-04-07

Jeśli funkcjonalność anti spam-captcha w PluXml w wersji 5.8.22 i wcześniejszych jest włączona, challenge captcha generowany jest w formacie, który można automatycznie rozpoznać dla artykułów, umożliwiając skryptom zautomatyzowanym trywialnym obejście tego mechanizmu i publikację spamowych komentarzy. Szczegóły challenge captcha są ujawniane w treści dokumentu artykułów z włączoną funkcjonalnością komentarzy i anti spam-captcha, w tym „capcha-letter", „capcha-word" i „capcha-token", które mogą być wykorzystane do konstruowania ważnego żądania post w celu publikacji komentarza. W rezultacie atakujący mogą zalewać artykuły zautomatyzowanymi spamowymi komentarzami, szczególnie jeśli brak dodatkowych ochrony na poziomie web.

Pokaż oryginał (EN)

If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that can be automatically recognized for articles, such that an automated script is able to solve this anti-spam mechanism trivially and publish spam comments. The details of captcha challenge are exposed within document body of articles with comments & anti spam-captcha functionalities enabled, including "capcha-letter", "capcha-word" and "capcha-token" which can be used to construct a valid post request to publish a comment. As such, attackers can flood articles with automated spam comments, especially if there are no other web defenses available.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  • Pluxml

    APP
    Pluxml
    ≤ 5.8.22
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2020-18185CRITICAL9.8PL ✓ten sam produkt

PluXml 5.7 — zdalne wykonanie kodu PHP przez modyfikację pliku konfiguracyjnego

CVE-2024-22636HIGH8.8ten sam produkt

PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages f...

CVE-2022-25018HIGH8.8ten sam produkt

Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into s...

CVE-2012-2227HIGH7.5ten sam produkt

Directory traversal vulnerability in update/index.php in PluXml before 5.1.6 allows remote attackers to includ...

CVE-2007-3432HIGH7.5ten sam produkt

Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload a...