Fallos del tipo CWE-804

18 resultados

CAPTCHA Previsível ou Facilmente Quebrável

Uma fraqueza onde o CAPTCHA usado para validar que um usuário é humano (e não um bot) utiliza uma lógica ou algoritmo tão simples que um atacante consegue adivinhar ou reproduzir a resposta correta sistematicamente. Isso anula completamente a proteção, permitindo automação de ataques como força bruta, preenchimento de cadastros spam ou roubo de conta.

Ejemplo

Um sistema gera CAPTCHAs cujas respostas são sequências numéricas previsíveis (ex: incrementando sempre em 1), ou usa um gerador de números aleatórios com seed fixo que pode ser replicado. Um atacante descobre o padrão e consegue automatizar o acesso sem intervenção humana real.

Cómo mitigar

Use bibliotecas CAPTCHA maduras e auditadas (como reCAPTCHA, hCaptcha), implemente lógica de desafio não-determinística com entropia criptográfica real, e valide sempre no servidor. Considere também rate-limiting e monitoramento de padrões anormais de tentativas.

CVE-2022-1801Very Simple Contact Form < 11.6 - Captcha bypassEPSS 1.2%CVE-2023-6963MEDIUMGetwid – Gutenberg Blocks <= 2.0.4 - Captcha BypassEPSS 0.5%CVE-2024-30540MEDIUMWordPress VS Contact Form plugin <= 14.7 - Sum Captcha Bypass vulnerabilityEPSS 0.5%CVE-2025-8546MEDIUMatjiu pybbs Verification Code login CaptchaEPSS 0.5%CVE-2022-4036MEDIUMAppointment Hour Booking <= 1.3.72 - CAPTCHA BypassEPSS 0.4%CVE-2025-10423MEDIUMnewbee-mall kaptcha mallKaptcha CaptchaEPSS 0.4%CVE-2024-31295MEDIUMWordPress Captcha by BestWebSoft plugin <= 5.2.0 - Captcha Bypass vulnerabilityEPSS 0.4%CVE-2026-49953MEDIUMDiscuz! X5.0 CAPTCHA Bypass via Predictable Character SetEPSS 0.4%CVE-2025-40916CRITICALMojolicious::Plugin::CaptchaPNG version 1.05 for Perl uses a weak random number source for generating the captcha textEPSS 0.4%CVE-2025-1262MEDIUMAdvanced Google reCaptcha <= 1.27 - Built-in Math CAPTCHA BypassEPSS 0.3%CVE-2025-32036MEDIUMDNN allows the possibility of bypassing CaptchaEPSS 0.3%CVE-2025-70129MEDIUMIf the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format thatEPSS 0.3%CVE-2025-50850HIGHAn issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such as CAPTCHA verificatiEPSS 0.2%CVE-2026-40935MEDIUMWWBN/AVideo has CAPTCHA Bypass via Attacker-Controlled Length Parameter and Missing Token Invalidation on FailureEPSS 0.2%CVE-2026-13082MEDIUMGD::SecurityImage versions through 1.75 for Perl use rand to generate secretsEPSS 0.2%CVE-2026-27411MEDIUMWordPress SiteGuard WP plugin plugin <= 1.7.9 - Captcha Bypass vulnerabilityEPSS 0.2%CVE-2024-23567MEDIUMHCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL paraEPSS 0.2%CVE-2024-23566MEDIUMHCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various securityEPSS 0.2%