CVE-2019-17240

CRITICAL

Bludit - Brute Force

Title source: rule

Description

bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.

Exploits (12)

exploitdb WORKING POC VERIFIED
by Mayank Deshmukh · pythonwebappsphp
https://www.exploit-db.com/exploits/48942
exploitdb WORKING POC VERIFIED
by Alexandre ZANNI · rubywebappsphp
https://www.exploit-db.com/exploits/48746
nomisec WORKING POC 3 stars
by pingport80 · poc
https://github.com/pingport80/CVE-2019-17240
nomisec WORKING POC 2 stars
by ColdFusionX · poc
https://github.com/ColdFusionX/CVE-2019-17240_Bludit-BF-Bypass
nomisec WORKING POC 1 stars
by 0xDTC · poc
https://github.com/0xDTC/Bludit-3.9.2-Auth-Bruteforce-Bypass-CVE-2019-17240
nomisec WORKING POC 1 stars
by spyx · poc
https://github.com/spyx/cve-2019-17240
gitlab WORKING POC
by quizno · poc
https://gitlab.com/quizno/cve-2019-17240-exploit
nomisec WORKING POC
by mind2hex · poc
https://github.com/mind2hex/CVE-2019-17240-Bludit-3.9.2-Auth-Bruteforce-Bypass
nomisec WORKING POC
by brunosergi · poc
https://github.com/brunosergi/bloodit
nomisec WORKING POC
by jayngng · poc
https://github.com/jayngng/bludit-CVE-2019-17240
nomisec WORKING POC
by triple-octopus · poc
https://github.com/triple-octopus/Bludit-CVE-2019-17240-Fork
nomisec WORKING POC
by LucaReggiannini · poc
https://github.com/LucaReggiannini/Bludit-3-9-2-bb

Scores

CVSS v3 9.8
EPSS 0.8263
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-307
Status published
Products (1)
bludit/bludit 3.9.2
Published Oct 06, 2019
Tracked Since Feb 18, 2026