#VU53058 Protection Mechanism Failure in Liferay Enterprise Portal - CVE-2021-29047
Published: May 11, 2021
Liferay Enterprise Portal
Liferay
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect SimpleCaptcha implementation, which does not invalidate CAPTCHA answers after they were used. A remote attacker can reuse the same CAPTCHA answers, bypass SimpleCaptcha protection and repeatedly perform actions with the web application.