iQ Block Country < 1.2.13 - Admin+ Arbitrary File Deletion via Zip Slip
CVE-2022-0246

4.9MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
11 April 2022

Summary

The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functionality. An authorized user can import preconfigured settings of the plugin by uploading a zip file. After the uploading process, files in the uploaded zip file are extracted one by one. During the extraction process, existence of a file is checked. If the file exists, it is deleted without any security control by only considering the name of the extracted file. This behavior leads to "Zip Slip" vulnerability.

Affected Version(s)

iQ Block Country 1.2.13

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ceylan Bozogullarindan
.