IPRateLimit Bypass Vulnerability in FileCodeBox by Vastsa
CVE-2025-51663
7.5HIGH
What is CVE-2025-51663?
A serious flaw exists in the IPRateLimit implementation of FileCodeBox, potentially allowing remote attackers to circumvent IP-based rate limiting and restrictions on failed attempts. By spoofing the X-Real-IP and X-Forwarded-For HTTP headers, attackers can execute denial-of-service (DoS) attacks or engage in brute force attempts on share codes, jeopardizing the security of user data and service availability.
