CVE-2019-13190: Medium severity knowage vulnerability
Published Sep 5, 2019
·Updated
In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in the signup page.
Affected Software
1 affected component
eng Knowage<=6.1.1
Event History
Sep 5, 2019
CVE Published
via MITRE·04:49 PM
Data Sourced
via MITRE·04:49 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13190?
CVE-2019-13190 has a medium severity rating due to its potential to allow unauthorized user registrations.
2
How do I fix CVE-2019-13190?
To fix CVE-2019-13190, upgrade Knowage to a version later than 6.1.1 where the CAPTCHA validation issue has been resolved.
3
What systems are affected by CVE-2019-13190?
CVE-2019-13190 affects Knowage versions up to and including 6.1.1.
4
What is the impact of exploiting CVE-2019-13190?
Exploiting CVE-2019-13190 allows attackers to bypass CAPTCHA protection on the signup page, potentially leading to spam registrations.
5
Is CVE-2019-13190 related to any other known vulnerabilities?
CVE-2019-13190 is specific to Knowage's CAPTCHA implementation and does not have known dependencies on other vulnerabilities.