Back to CVE List

CVE-2026-64619

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Vulnerability Description

FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling by supplying attacker-controlled X-Real-IP and X-Forwarded-For headers without verification of trusted reverse proxy origin. Attackers can supply unique spoofed IP values on each request to enumerate all possible share codes and retrieve other users' files without authentication.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-348
Source
NVD
Vendor
vastsa
Product
FileCodeBox

External References

Discussion (0)

Add Comment

No comments yet. Be the first!