Author Topic: Captcha can be bypassed  (Read 6214 times)

aussiefrog

  • Guest
Captcha can be bypassed
« on: July 24, 2017, 11:03:37 PM »
I am using 1.2.10

When creating a new account the captcha can be bypassed using these instructions:

- Fill in all required fields
- Submit the form (ignoring captcha or after it has failed)
- Refresh the page with F5

The form will be successfully submitted without a valid captcha.

This does not work for the contact form.

Can you please address this?


Offline Basara

  • Administrator
  • Hero Member
  • *****
  • Posts: 5774
  • Karma: +274/-2
    • View Profile
Re: Captcha can be bypassed
« Reply #1 on: July 25, 2017, 02:35:38 AM »
Hello, thank you for reporting issue.

It is already fixed in 1.2.11 version please see this commit https://github.com/abantecart/abantecart-src/commit/d2a5c5700f3eb3caf561e5b45a04697d41f111d5

You can try to replace your public_html/storefront/controller/pages/account/create.php file with new from 1.2.11

 

Powered by SMFPacks Social Login Mod