CVE-2021-29047Improper Authentication in DXP

Severity
7.5HIGHNVD
EPSS
0.3%
top 47.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 16
Latest updateMay 24

Description

The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCHA challenge by reusing the same CAPTCHA answer.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDliferay/liferay_portal7.3.4, 7.3.5+1
NVDliferay/dxp< 7.3+1

🔴Vulnerability Details

3
GHSA
Liferay Portal and Liferay DXP Fails to Invalidate CAPTCHA Answers After Use2022-05-24
OSV
Liferay Portal and Liferay DXP Fails to Invalidate CAPTCHA Answers After Use2022-05-24
CVEList
CVE-2021-29047: The SimpleCaptcha implementation in Liferay Portal 72021-05-16
CVE-2021-29047 — Improper Authentication in Liferay DXP | cvebase