CAPTCHA Protected Page
Anyone without logging in could create a fake digital token to trick the website into thinking they had already passed the human verification test. This would allow automated bots to read protected pages. They could not change any information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate CAPTCHA Protected Page to 1.0.2.
For developers: what the fix changed
The fix replaces the static 'verified' cookie value with a token signed using HMAC containing the protected path and expiration time, generated in `CaptchaForm::createCookie()` and validated in `CaptchaRedirectSubscriber::onKernelRequest()`.
Also in this release Added Drupal 11 compatibility.
captcha_protected_page.info.yml+1 −1captcha_protected_page.services.yml+2 −2 fixsrc/EventSubscriber/CaptchaRedirectSubscriber.php+89 −6 fixsrc/Form/CaptchaForm.php+59 −6 fix