Junglewise Threat Intelligence

strapi-plugin-ezforms captcha bypass

Severity: info · Published 2022-08-30

Vendors: npm.

Executive brief

strapi-plugin-ezforms is a form plugin for the Strapi headless CMS that integrates with captcha services like Google reCAPTCHA to protect forms from automated abuse. A vulnerability in the plugin allows attackers to bypass captcha validation entirely, causing the plugin to send form submissions and email notifications even when captcha checks fail. This enables spam, automated attacks, and potential abuse of email systems.

Technical details

The vulnerability is a captcha validation bypass in the strapi-plugin-ezforms plugin. The root cause is improper validation of captcha responses—specifically, the plugin does not correctly check the captcha provider's score/status before processing and sending form submissions. An attacker can submit forms with invalid or missing captcha tokens, and the plugin will process them regardless. This occurs because the validation logic fails to enforce captcha checks, allowing email notifications to be sent and form data to be processed without proper verification. The plugin is patched in version 0.1.0 and later. No network access restrictions apply; the vulnerability is exploitable by any user with access to the form interface.

Affected products

  • excl-networks strapi-plugin-ezforms <0.1.0

Timeline

  • 2022-08-25: disclosed
  • 2022-08-30: patched: Version 0.1.0 and later

References