bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.
References
Configurations
History
No history.
Information
Published : 2019-10-06 19:15
Updated : 2020-10-21 18:15
NVD link : CVE-2019-17240
Mitre link : CVE-2019-17240
CVE.ORG link : CVE-2019-17240
JSON object : View
Products Affected
bludit
- bludit
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts