Captcha Bypass enable login bruteforce

Disclosed: 2016-05-13 17:59:55 By bugs3ra To veris
Unknown
Vulnerability Details
HI There is captcha bypass, which can lead to login credentials bruteforce attack. Just remove **&g-recaptcha-response** from request, and the server accepts your request. Please check the screenshots...
Actions
View on HackerOne
Report Stats
  • Report ID: 124173
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report