CVE detail
CVE-2019-17240 — CVE-2019-17240
Published 2019-10-06 · Modified 2026-06-17 · Vendor bludit · Product bludit · Source nvd
CRITICAL
severity
CVSS-derived band
0.3960
EPSS probability
exploitation probability, 30d
98.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References