An IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP address with any arbitrary IP address, specifically by adding a forged 'X-Forwarded' or 'Client-IP' header to requests. Exploiting IP spoofing, attackers can bypass account lockout mechanisms during attempts to log into admin accounts, spoof IP addresses in requests sent to the server, and impersonate IP addresses that have logged into user accounts, etc.
History

Thu, 08 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:likeshop:likeshop:*:*:*:*:*:*:*:*

Wed, 07 Aug 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Likeshop
Likeshop likeshop
Weaknesses CWE-290
CPEs cpe:2.3:a:likeshop:likeshop:-:*:*:*:*:*:*:*
Vendors & Products Likeshop
Likeshop likeshop
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
Description An IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP address with any arbitrary IP address, specifically by adding a forged 'X-Forwarded' or 'Client-IP' header to requests. Exploiting IP spoofing, attackers can bypass account lockout mechanisms during attempts to log into admin accounts, spoof IP addresses in requests sent to the server, and impersonate IP addresses that have logged into user accounts, etc.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-08-07T00:00:00

Updated: 2024-08-07T17:31:22.277Z

Reserved: 2024-07-18T00:00:00

Link: CVE-2024-41432

cve-icon Vulnrichment

Updated: 2024-08-07T17:31:13.862Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-07T16:15:46.130

Modified: 2024-08-08T15:02:52.647

Link: CVE-2024-41432

cve-icon Redhat

No data.