Total vulnerabilities in the database
Pedro Lineu Orso chetcpasswd before 2.4 relies on the X-Forwarded-For HTTP header when verifying a client's status on an IP address ACL, which allows remote attackers to gain unauthorized access by spoofing this header.
Software | From | Fixed in |
---|---|---|
chetcpasswd_project / chetcpasswd | - | 2.4 |