Home

Description

A vulnerability found in IPRateLimit implementation of FileCodeBox up to 2.2 allows remote attackers to bypass ip-based rate limit protection and failed attempt restrictions by faking X-Real-IP and X-Forwarded-For HTTP headers. This can enable attackers to perform DoS attacks or brute force share codes.

PUBLISHED Reserved 2025-06-16 | Published 2025-11-19 | Updated 2025-11-20 | Assigner mitre

References

github.com/vastsa/FileCodeBox

github.com/vastsa/FileCodeBox/issues/350

cve.org (CVE-2025-51663)

nvd.nist.gov (CVE-2025-51663)

Download JSON