7.5
CVE-2022-1762
- EPSS 0.25%
- Veröffentlicht 13.06.2022 13:15:12
- Zuletzt bearbeitet 21.11.2024 06:41:24
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
iQ Block Country <= 1.2.13 - Protection Bypass due to IP Spoofing
The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.
Mögliche Gegenmaßnahme
iQ Block Country: Update to version 1.2.17, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
iQ Block Country
Version
* - 1.2.13
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Webence ≫ Iq Block Country SwPlatformwordpress Version <= 1.2.13
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.476 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|