Loading HuntDB...

Captcha checker "pd-captcha_form_SURVEYID" cookie is accepting any value

Medium
A
Automattic
Submitted None
Reported by bugra

Vulnerability Details

Technical details and impact analysis

Improper Access Control - Generic
## Summary: Hi team, There is a `Captcha protection` feature on surveys and polls. If you captcha protection enabled survey, you will see this : {F901789} When you solve captcha and click `Submit Captcha`, website sets a cookie like this : {F901799} And if you delete this cookie and try access to survey, you will see captcha again. But if you change value of this cookie, you can access still. So any attacker can bypass this restriction via typing random value to cookie. ## Steps To Reproduce: 1. Go to a captcha protected survey or poll 1. Solve the captcha and click `Submit Captcha` 1. Now change the value of `pd-captcha_form_SURVEYID` cookie to random value from browser's console. 1. Refresh the page and you will see you can access to survey and submit the survey. ## Impact Bypassing captcha protection on surveys and polls Thanks, Bugra

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic