First published: Tue Oct 25 2016(Updated: )
TGCaptcha2 version 0.3.0 is vulnerable to a replay attack due to a missing nonce allowing attackers to use a single solved CAPTCHA multiple times.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Python Tgcaptcha2 | =0.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1000032 has been classified as a moderate severity vulnerability.
CVE-2016-1000032 allows attackers to exploit a replay attack due to the absence of a nonce in TGCaptcha2 version 0.3.0.
CVE-2016-1000032 is associated with replay attacks that permit multiple uses of a single solved CAPTCHA.
To mitigate CVE-2016-1000032, update TGCaptcha2 to a version that includes nonce support to prevent replay attacks.
Yes, CVE-2016-1000032 can compromise your web application's security by allowing attackers to bypass CAPTCHA protection.