{"id":"CVE-2021-29047","title":"The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCH…","summary":"The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCH…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-287"],"vendor":"liferay","product":"dxp","affected":["dxp < 7.3","dxp = 7.3","liferay_portal = 7.3.4","liferay_portal = 7.3.5"],"patched":["dxp 7.3"],"published":"2021-05-16","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-29047","references":[{"url":"https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120743467","label":"cve@mitre.org"},{"url":"http://liferay.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120743467","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01065,"epssPercentile":0.63226,"ingestedAt":"2026-07-05T02:00:01.596Z","slug":"CVE-2021-29047","body":"## Overview\n\nThe SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCHA challenge by reusing the same CAPTCHA answer.\n\n## Affected\n\n- `dxp < 7.3`\n- `dxp = 7.3`\n- `liferay_portal = 7.3.4`\n- `liferay_portal = 7.3.5`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `dxp 7.3`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}