Project

General

Profile

Actions

Bug #91441

open

Security problem with form extension form_formframework

Added by Martin Weymayer almost 4 years ago. Updated over 3 years ago.

Status:
New
Priority:
Should have
Assignee:
-
Category:
-
Target version:
-
Start date:
2020-05-19
Due date:
% Done:

0%

Estimated time:
TYPO3 Version:
10
PHP Version:
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

We have detected, that spammer are able to send mails via form extension form_formframework also having javavscript and google recaptcha spam protection. so we think spammer use some sercury problem in form_formframework. TYPO3 8 - 10 have same problem.

We found out, that spammer somehow find out correct post parameter and then send each 2 minutes only post parameter. so maybe a timestamp can help a little bit. set a timestam to hidden field and validate if form is submitted to fast (f. e. 10 seconds) or timestamp is too old (2 minutes).


Files

spam.jpg (902 KB) spam.jpg Martin Weymayer, 2020-05-19 12:43
Actions

Also available in: Atom PDF