vendor:
Drupal
by:
Michele Orru
7.5
CVSS
HIGH
Security Bypass
287
CWE
Product Name: Drupal
Affected Version From: Drupal CAPTCHA module versions prior to 6.x-2.3 and 7.x-1.0
Affected Version To: Drupal CAPTCHA module versions prior to 6.x-2.3 and 7.x-1.0
Patch Exists: YES
Related CWE:
CPE: a:drupal:drupal
Platforms Tested:
2011
CAPTCHA Module Security Bypass Vulnerability in Drupal
The CAPTCHA module in Drupal is prone to a security-bypass vulnerability that occurs in the CAPTCHA authentication routine. Successful exploits may allow attackers to bypass the CAPTCHA-based authentication routine, allowing attackers to perform brute-force attacks.
Mitigation:
Apply the latest security patches provided by Drupal. Implement additional security measures such as IP blocking and account lockout policies.