Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xxg2-xvp8-vqm5

Опубликовано: 13 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-based rate limiting and ban enforcement by trusting untrusted HTTP headers. Attackers can set HTTP_CLIENT_IP or HTTP_X_FORWARDED_FOR headers to spoof their IP address and circumvent security controls.

wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-based rate limiting and ban enforcement by trusting untrusted HTTP headers. Attackers can set HTTP_CLIENT_IP or HTTP_X_FORWARDED_FOR headers to spoof their IP address and circumvent security controls.

EPSS

Процентиль: 5%
0.00019
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-348

Связанные уязвимости

CVSS3: 5.3
nvd
14 дней назад

wpDiscuz before 7.6.47 contains an IP spoofing vulnerability in the getIP() function that allows attackers to bypass IP-based rate limiting and ban enforcement by trusting untrusted HTTP headers. Attackers can set HTTP_CLIENT_IP or HTTP_X_FORWARDED_FOR headers to spoof their IP address and circumvent security controls.

EPSS

Процентиль: 5%
0.00019
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-348