CVE-2026-64797
N/A
N/A
Summary
IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| regularlabs.com | IP Login extension for Joomla | 1.0.0-6.2.5 | affected |
Weaknesses
- CWE-290: CWE-290 Authentication Bypass by Spoofing
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.