Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-02271
HistoryNov 21, 2022 - 12:00 a.m.

WBCE CMS Access Control Error Vulnerability

2022-11-2100:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
wbce cms
access control error
vulnerability
php
mysql
x-forwarded-for parameter
authentication

0.001 Low

EPSS

Percentile

48.6%

WBCE CMS is an open source content management system (CMS) based on PHP and MySQL.WBCE CMS is vulnerable to an access control error that originates in the increase_attempts function of the wbce/framework/class.login.php file in its Header Handler component for X -Forwarded-For parameter does not properly limit too many authentication attempts. An attacker could exploit the vulnerability to authenticate unrestrictedly.

0.001 Low

EPSS

Percentile

48.6%

Related for CNVD-2023-02271