CyberRota Analysis
AI-GeneratedZoraxy versions 3.2.3 through 3.3.4 are vulnerable due to improper parsing of IPv6 addresses in the RemoteAddr field, allowing unauthenticated attackers to manipulate X-Forwarded-For values. This vulnerability enables attackers to spoof their source IP addresses, potentially bypassing IP-based access controls and compromising system security. Organizations using affected Zoraxy versions should prioritize patching to mitigate the risk of unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their source IP and bypass authorization provider IP-based access controls.