CN
CyberNewsUz
Threat Intelligence Portal
LOADING0%
CyberNewsUz
Threat Intelligence Portal
CyberNewsUz
Threat Intelligence Portal
7.6.47 versiyasidan oldingi wpDiscuz getIP() funksiyasida IP soxtalashtirish zaifligini o'z ichiga oladi, bu esa hujumchilarga ishonchsiz HTTP sarlavhalariga ishonish orqali IP asosidagi tezlikni cheklash va taqiqlashni chetlab o'tish imkonini beradi. Hujumchilar HTTP_CLIENT_IP yoki HTTP_X_FORWARDED_FOR sarlavhalarini o'zlarining IP manzillarini soxtalashtirish va xavfsizlikni boshqarish vositalarini chetlab o'tish uchun sozlashlari mumkin.
Vendor
β
Product
β
CVSS Score
5.3
Nashr sanasi
13-mar, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N