SB2016102810 - Security Features in dotCMS
Published: October 28, 2016 Updated: August 9, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Security Features (CVE-ID: CVE-2016-8600)
The vulnerability allows a remote non-authenticated attacker to manipulate data.
In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.
Remediation
Install update from vendor's website.