In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://github.com/walinejs/waline/issues/785 | third party advisory issue tracking exploit |
https://github.com/walinejs/waline/discussions/792 | third party advisory patch |