What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Qode Qi Blocks qi-blocks.This issue affects Qi Blocks: from n/a through <= 1.3.2.
Explanation of Vulnerability in Simple Terms
Qi Blocks versions 1.3.2 and earlier contain a code injection vulnerability accessible to authenticated users with low privileges. An attacker can inject and execute arbitrary code on the site, potentially compromising the entire installation. The vulnerability requires network access and high attack complexity but no user interaction. All confidentiality, integrity, and availability of the site are at risk.
What an attacker can do
Run arbitrary code on the site with the privileges of the authenticated user account.
Potential impact on your site
A low-privilege user account can compromise the entire site, including data theft, malware injection, and service disruption.
Conditions required to exploit
Attacker must have a low-privilege authenticated account; network access required.
Key dates
External resources
Related vulnerabilities