### [CVE-2024-35538](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35538) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as value of X-Forwarded-For or Client-Ip headers while performing HTTP requests. ### POC #### Reference - https://cyberaz0r.info/2024/08/typecho-multiple-vulnerabilities/ #### Github - https://github.com/nomi-sec/PoC-in-GitHub