A vulnerability marked as problematic has been reported in vastsa FileCodeBox up to 2.3. This impacts an unknown function of the component IPRateLimit. The manipulation of the argument X-Real-IP/X-Forwarded-For leads to information disclosure.
This vulnerability is documented as CVE-2026-64619. The attack can be initiated remotely. There is not any exploit available.