Vendor
medium
advisory
Race Condition Vulnerability in FileCodeBox
1 CVEA race condition vulnerability in the update_file_usage function of FileCodeBox versions up to 2.3 allows remote attackers to manipulate file usage limits.
FileCodeBox
1c
high
advisory
CVE-2026-64619: FileCodeBox Rate Limit Bypass Vulnerability
2 TTPs 1 CVE 4 IOCsUnauthenticated attackers can bypass rate limits in FileCodeBox versions before 2.4 due to a vulnerability in the IPRateLimit class, allowing them to enumerate share codes and retrieve other users' files without authentication by spoofing X-Real-IP and X-Forwarded-For headers without proper verification.
FileCodeBox
rate-limit-bypass
vulnerability
web-application
file-sharing
data-exfiltration
cve
2t
1c
4i