Vulnerabilities (CVE)

Filtered by vendor Flask-session-captcha Project
Filtered by product Flask-session-captcha
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-24880 1 Flask-session-captcha Project 1 Flask-session-captcha 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
flask-session-captcha is a package which allows users to extend Flask by adding an image based captcha stored in a server side session. In versions prior to 1.2.1, he `captcha.validate()` function would return `None` if passed no value (e.g. by submitting an having an empty form). If implementing users were checking the return value to be **False**, the captcha verification check could be bypassed. Version 1.2.1 fixes the issue. Users can workaround the issue by not explicitly checking that the ...

Show More