CVE-2019-17240
CRITICALBludit - Brute Force
Title source: ruleDescription
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.
Exploits (12)
exploitdb
WORKING POC
VERIFIED
by Mayank Deshmukh · pythonwebappsphp
https://www.exploit-db.com/exploits/48942
exploitdb
WORKING POC
VERIFIED
by Alexandre ZANNI · rubywebappsphp
https://www.exploit-db.com/exploits/48746
nomisec
WORKING POC
2 stars
by ColdFusionX · poc
https://github.com/ColdFusionX/CVE-2019-17240_Bludit-BF-Bypass
nomisec
WORKING POC
1 stars
by 0xDTC · poc
https://github.com/0xDTC/Bludit-3.9.2-Auth-Bruteforce-Bypass-CVE-2019-17240
nomisec
WORKING POC
by mind2hex · poc
https://github.com/mind2hex/CVE-2019-17240-Bludit-3.9.2-Auth-Bruteforce-Bypass
nomisec
WORKING POC
by triple-octopus · poc
https://github.com/triple-octopus/Bludit-CVE-2019-17240-Fork
References (4)
Scores
CVSS v3
9.8
EPSS
0.8263
EPSS Percentile
99.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-307
Status
published
Products (1)
bludit/bludit
3.9.2
Published
Oct 06, 2019
Tracked Since
Feb 18, 2026