CVE-2024-44821

MEDIUM

ZZCMS < 2023 - Improper Authentication via Captcha Reuse Logic

Title source: llm
STIX 2.1

Description

ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the captcha value after a failed validation attempt. As a result, an attacker can exploit this flaw by repeatedly submitting the same incorrect captcha response, allowing them to capture the correct captcha value through error messages.

Scores

CVSS v3 5.3
EPSS 0.0042
EPSS Percentile 33.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (1)
zzcms/zzcms < 2023
Published Sep 04, 2024
Tracked Since Feb 18, 2026