PT-2026-61697 · Unknown · Filecodebox
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FileCodeBox versions prior to 2.4
Description
A rate-limit bypass exists in the
IPRateLimit class that allows unauthenticated attackers to circumvent request throttling. This occurs because the system does not verify the origin of trusted reverse proxies when processing the X-Real-IP and X-Forwarded-For headers. By supplying unique spoofed IP values in these headers for each request, an attacker can enumerate share codes and retrieve files belonging to other users without authentication.Recommendations
Update to version 2.4 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Filecodebox