CVE-2024-41432
Last modified
CVE-2024-41432 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP address with any arbitrary IP address, specifically by adding a forged 'X-Forwarded' or 'Client-IP' header to requests. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
An IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP address with any arbitrary IP address, specifically by adding a forged 'X-Forwarded' or 'Client-IP' header to requests. Exploiting IP spoofing, attackers can bypass account lockout mechanisms during attempts to log into admin accounts, spoof IP addresses in requests sent to the server, and impersonate IP addresses that have logged into user accounts, etc.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Likeshop | Likeshop | <= 2.5.7.20210811 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-41432?
How severe is CVE-2024-41432?
How do I fix CVE-2024-41432?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-41381microweber 2.0.16 was discovered to contain a Cross Site Scr…6.1
- CVE-2024-4139Manage Bank Statement ReProcessing Rules does not perform ne…4.3
- CVE-2024-4140An excessive memory use issue (CWE-770) exists in Email-MIME…7.5
- CVE-2024-4141Out-of-bounds array write in Xpdf 4.05 and earlier, triggere…5.5
- CVE-2024-4142An Improper input validation vulnerability that could potent…9
- CVE-2024-4143A potential security vulnerability has been identified in ce…9.8
- CVE-2024-41433PingCAP TiDB v8.1.0 was discovered to contain a buffer overf…9.8
- CVE-2024-41434PingCAP TiDB v8.1.0 was discovered to contain a buffer overf…4.3
- CVE-2024-41435YugabyteDB v2.21.1.0 was discovered to contain a buffer over…7.5
- CVE-2024-41436ClickHouse v24.3.3.102 was discovered to contain a buffer ov…7.5
- CVE-2024-41437A heap buffer overflow in the function cp_unfilter() (/vendo…5.5
- CVE-2024-41438A heap buffer overflow in the function cp_stored() (/vendor/…6.2
Are you affected by CVE-2024-41432?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
