Impact
The vulnerability is an authentication bypass that allows an attacker to gain unauthorized access to protected resources by exploiting an alternate path or channel in the Drupal CAPTCHA Protected Page module. The flaw arises from incorrect handling of authentication flow, enabling the bypass of CAPTCHA‑based access control. This flaw is identified as CWE‑288, indicating Unauthorized Access. If successfully exploited, it could allow attackers to read or modify sensitive data, compromise system integrity, or elevate privileges without legitimate authentication.
Affected Systems
The affected systems are Drupal CAPTCHA Protected Page modules with versions ranging from 0.0.0 up to and including 1.0.2. These releases are susceptible if the module is used to protect authentication or access control for administrative or restricted pages on a site.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The risk assessment indicates that, while no public exploits have been documented, the bug permits a straightforward bypass of authentication controls. The likely attack vector is via HTTP requests that exploit the alternate path handling logic, and an attacker only needs to reach the CAPTCHA protected page to attempt the bypass. The potential impact includes unauthorized access to sensitive content or administrative functions, jeopardizing confidentiality and integrity. Given its moderate severity, the vulnerability warrants prompt attention. The CVSS score of 3.7 signifies moderate severity.
OpenCVE Enrichment