altcha-org/altcha is vulnerable to Improper Neutralization of Parameter/Argument Delimiters
56
Medium Risk
Affected versions of this package are vulnerable to a parameter splicing vulnerability in the salt handling logic where the application failed to consistently enforce a delimiter, allowing an attacker to exploit this by injecting a custom delimiter into the salt parameter to maliciously splice and control the resulting composite string, thereby enabling authentication bypass or replay attacks where a previously observed hashed value could be fraudulently reused.
You are affected if you are using a version that falls within the vulnerable range.
altcha-org/altcha is vulnerable to Improper Neutralization of Parameter/Argument Delimiters in versions 0.1.0 - 1.3.0.
Upgrade the altcha-org/altcha library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant