7.5
CVE-2022-1762
- EPSS 1.16%
- Veröffentlicht 13.06.2022 13:15:12
- Zuletzt bearbeitet 21.11.2024 06:41:24
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
iQ Block Country < 1.2.20 - Protection Bypass due to IP Spoofing
iQ Block Country <= 1.2.13 - Protection Bypass due to IP Spoofing
The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.
Mögliche Gegenmaßnahme
iQ Block Country: Update to version 1.2.17, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Webence ≫ Iq Block Country SwPlatformwordpress Version <= 1.2.13
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
iQ Block Country
Version
*-1.2.13
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.16% | 0.631 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
https://wpscan.com/vulnerability/03254977-37cc-4365-979b-326f9637be85
https://www.wordfence.com/threat-intel/vulnerabilities/id/5f388049-b453-406c-abdf-2a51c7abed2d