← volver
CVE-2022-0246CWE-73

iQ Block Country < 1.2.13 - Admin+ Arbitrary File Deletion via Zip Slip

3Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackepss 3.3%
probabilidad de explotación
3.3%top 13% de las CVE
explotación observada
noninguna fuente lo reporta
The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functionality. An authorized user can import preconfigured settings of the plugin by uploading a zip file. After the uploading process, files in the uploaded zip file are extracted one by one. During the extraction process, existence of a file is checked. If the file exists, it is deleted without any security control by only considering the name of the extracted file. This behavior leads to "Zip Slip" vulnerability.
Productos afectados
Unknown · iQ Block Country