Back to overview

CVE-2026-64619

HIGH
7.5
CVSS 3.1
Description
FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling by supplying attacker-controlled X-Real-IP and X-Forwarded-For headers without verification of trusted reverse proxy origin. Attackers can supply unique spoofed IP values on each request to enumerate all possible share codes and retrieve other users' files without authentication.

Metadata

CVE ID
CVE-2026-64619
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-07-20 11:58 UTC
Published
2026-07-20 18:50 UTC
Last updated
2026-07-21 11:08 UTC
Primary CWE
CWE-348
Use of Less Trusted Source
Vendor / Product
vastsa / FileCodeBox
Sources
cve.org  ·  NVD

Severity & Metrics

7.5 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
vastsa FileCodeBox 0 < 2.4
Weakness (CWE)
CWESourceDescription
CWE-348 cna Use of Less Trusted Source
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.7 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
7.5 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Back to overview