PT-2025-49680 · Wbce Cms · Wbce Cms

Published

2025-12-08

·

Updated

2025-12-22

·

CVE-2025-66204

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WBCE CMS versions prior to 1.6.5
Description WBCE CMS is a content management system susceptible to a brute-force protection bypass. An attacker can reset the attempt counter by manipulating the X-Forwarded-For header with each request, enabling unlimited password guessing attempts. The application trusts the X-Forwarded-For header without validation or restriction. The vulnerable parameter is X-Forwarded-For.
Recommendations Update to WBCE CMS version 1.6.5 or later.

Exploit

Fix

Protection Mechanism Failure

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2025-66204
GHSA-F676-F375-M7MW

Affected Products

Wbce Cms