CVE-2022-0246
iQ Block Country < 1.2.13 - Admin+ Arbitrary File Deletion via Zip Slip
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functionality. An authorized user can import preconfigured settings of the plugin by uploading a zip file. After the uploading process, files in the uploaded zip file are extracted one by one. During the extraction process, existence of a file is checked. If the file exists, it is deleted without any security control by only considering the name of the extracted file. This behavior leads to "Zip Slip" vulnerability.
La configuración del plugin iQ Block Country de WordPress versiones anteriores a 1.2.13, puede exportarse o importarse usando su funcionalidad backup. Un usuario autorizado puede importar los ajustes preconfigurados del plugin subiendo un archivo zip. Tras el proceso de carga, los archivos del archivo zip cargado son extraídos uno a uno. Durante el proceso de extracción, es comprobado la existencia de un archivo. Si el archivo se presenta, es eliminado sin ningún control de seguridad teniendo en cuenta únicamente el nombre del archivo extraído. Este comportamiento conlleva a una vulnerabilidad "Zip Slip"
WordPress iQ Block Country plugin version 1.2.13 suffers from an arbitrary file deletion vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-17 CVE Reserved
- 2022-03-16 CVE Published
- 2022-03-21 First Exploit
- 2024-08-02 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-73: External Control of File Name or Path
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/166370 | 2022-03-21 | |
https://wpscan.com/vulnerability/892802b1-26e2-4ce1-be6f-71ce29687776 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Webence Search vendor "Webence" | Iq Block Country Search vendor "Webence" for product "Iq Block Country" | < 1.2.13 Search vendor "Webence" for product "Iq Block Country" and version " < 1.2.13" | wordpress |
Affected
|