CVE-2017-11717
Last modified
CVE-2017-11717 is a vulnerability of currently unknown severity. MetInfo through 5.3.17 accepts the same CAPTCHA response for 120 seconds, which makes it easier for remote attackers to bypass intended challenge requirements by modifying the client-server data stream, as demonstrated by the login/findpass page.. EPSS estimates a 1.13% chance of exploitation in the next 30 days.
Description
MetInfo through 5.3.17 accepts the same CAPTCHA response for 120 seconds, which makes it easier for remote attackers to bypass intended challenge requirements by modifying the client-server data stream, as demonstrated by the login/findpass page.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Metinfo Project | Metinfo | <= 5.3.17 |
References
- https://lncken.cn/?p=343Third Party Advisory
- https://lncken.cn/?p=343Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-11717?
How severe is CVE-2017-11717?
How do I fix CVE-2017-11717?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-11705A memory leak was found in the function parseSWF_SHAPEWITHST…
- CVE-2017-11706The Boozt Fashion application before 2.3.4 for Android allow…
- CVE-2017-1171The IBM TRIRIGA Application Platform 3.3, 3,4, and 3,5 conta…
- CVE-2017-11714psi/ztoken.c in Artifex Ghostscript 9.21 mishandles referenc…
- CVE-2017-11715job/uploadfile_save.php in MetInfo through 5.3.17 blocks the…
- CVE-2017-11716MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode.
- CVE-2017-11718There is URL Redirector Abuse in MetInfo through 5.3.17 via …
- CVE-2017-11719The dnxhd_decode_header function in libavcodec/dnxhddec.c in…
- CVE-2017-11720There is a division-by-zero vulnerability in LAME 3.99.5, ca…
- CVE-2017-11721Buffer overflow in ioquake3 before 2017-08-02 allows remote …
- CVE-2017-11722The WriteOnePNGImage function in coders/png.c in GraphicsMag…
- CVE-2017-11723Directory traversal vulnerability in plugins/ImageManager/ba…
Are you affected by CVE-2017-11717?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
