CVE-2025-66204

Source
https://cve.org/CVERecord?id=CVE-2025-66204
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66204.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-66204
Aliases
  • GHSA-f676-f375-m7mw
Published
2025-12-08T23:50:58.647Z
Modified
2026-04-02T13:01:08.230012Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
WBCE CMS allows brute-force protection bypass using X-Forwarded-For header
Details

WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can indefinitely reset the counter by modifying X-Forwarded-For on each request, gaining unlimited password guessing attempts, effectively bypassing all brute-force protection. The application fully trusts the X-Forwarded-For header without validating it or restricting its usage. This issue is fixed in version 1.6.5.

Database specific
{
    "cwe_ids": [
        "CWE-307",
        "CWE-693"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66204.json"
}
References

Affected packages

Git / github.com/wbce/wbce_cms

Affected ranges

Type
GIT
Repo
https://github.com/wbce/wbce_cms
Events

Affected versions

1.*
1.6.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66204.json"