PT-2022-13064 · WordPress · Iq Block Country

Ceylan Bozogullarindan

·

Published

2022-04-11

·

Updated

2022-04-15

·

CVE-2022-0246

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions iQ Block Country WordPress plugin versions prior to 1.2.13
Description The issue allows an authorized user to import preconfigured settings of the plugin by uploading a zip file. During the extraction process of the uploaded zip file, files are extracted one by one and their existence is checked. If a file exists, it is deleted without any security control, considering only the name of the extracted file. This behavior leads to a "Zip Slip" vulnerability.
Recommendations For versions prior to 1.2.13, update to version 1.2.13 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0246

Affected Products

Iq Block Country