Impact
FileCodeBox a flaw in the IPRateLimit implementation that allows an attacker to bypass request throttling. By sending requests with attacker‑controlled "X-Real-IP" and "X-Forwarded-For" headers that are not verified as originating from a trusted reverse proxy, the rate‑limit can be circumvented. This is a CWE-348 vulnerability. The consequence is that an unauthenticated attacker can enumerate every possible share code and download files belonging to other users without authentication, exposing private data.
Affected Systems
All installations of FileCodeBox built before the 2.4 release are affected. The vendor, vastsa, released version 2.4 with the fix at the indicated release tag.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. The EPSS score is less than 1%, indicating a very low exploitation probability. The lack of a KEV listing does not diminish its risk. Based on the description, the likely attack vector is remotely issuing standard HTTP requests from anywhere on the internet, relying only on the ability to set the spoofed headers.
OpenCVE Enrichment