CVE-2026-64797
Description
IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| regularlabs.com | IP Login extension for Joomla | — | 1.0.0-6.2.5 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-290 | cna | CWE-290 Authentication Bypass by Spoofing |
References (1)