CVE-2019-16699

The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and below for TYPO3 fails to sanitize user input, which allows execution of arbitrary Extbase actions, resulting in Remote Code Execution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sr_freecap_project:sr_freecap:*:*:*:*:*:*:*:*
cpe:2.3:a:sr_freecap_project:sr_freecap:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-10-16 19:15

Updated : 2024-02-04 20:39


NVD link : CVE-2019-16699

Mitre link : CVE-2019-16699

CVE.ORG link : CVE-2019-16699


JSON object : View

Products Affected

sr_freecap_project

  • sr_freecap
CWE
CWE-20

Improper Input Validation