IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://regularlabs.com/ |
|
History
Wed, 22 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts. | |
| Title | Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension | |
| Weaknesses | CWE-290 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-07-22T20:44:08.843Z
Reserved: 2026-07-20T18:16:31.593Z
Link: CVE-2026-64797
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses