CVE-2024-44821

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
04/09/2024
Last modified:
23/04/2025

Description

ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the captcha value after a failed validation attempt. As a result, an attacker can exploit this flaw by repeatedly submitting the same incorrect captcha response, allowing them to capture the correct captcha value through error messages.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zzcms:zzcms:*:*:*:*:*:*:*:* 2023 (including)