Vulnerabilities > CVE-2014-2224 - 7PK - Security Features vulnerability in Plogger 1.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
plogger
CWE-254

Summary

Plogger 1.0 RC1 and earlier, when the Lucid theme is used, does not assign new values for certain codes, which makes it easier for remote attackers to bypass the CAPTCHA protection mechanism via a series of form submissions.

Vulnerable Configurations

Part Description Count
Application
Plogger
1

Common Weakness Enumeration (CWE)