CWE-804Base

Guessable CAPTCHA

Incomplete in the CWE catalog · 16 CVEs mapped

16
CVEs mapped
5.3
Median CVSS
What it is

The product uses a CAPTCHA challenge, but the challenge can be guessed or automatically recognized by a non-human actor.

Recent examples
6.5cvss
CVE-2024-23566

HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented

HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration

MEDIUMno explanation yet
0%
epss
4.3cvss
CVE-2024-23567

HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during…

HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy logs.

MEDIUMno explanation yet
0%
epss
5.3cvss
CVE-2026-13082

GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets

GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge text used for the CAPTCHA by sampling characters from an array using Perl's built-in rand function, and generates a (by default) six-character string. The built-in rand function is unsuitable for security applications because it is predictable and reversible.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-804
Abstraction
Base
Structure
Simple
Status
Incomplete
References (1)