Skip to content

Insufficient reCAPTCHA response verification #560

@plr0man

Description

@plr0man

It looks like reCAPTCHA is not correctly implemented and the protection can be easily bypassed. Not providing exact details here to not expose organizations that are using this fork to bot attacks, but the bypass is trivial and has been confirmed in testing. Please make sure to correctly verify the value of g-recaptcha-response when sending invites.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions