9

CVE-2021-24307

Exploit

All in One SEO Pack < 4.1.0.2 - Admin RCE via unserialize

All in One SEO <= 4.1.0.1 - Authenticated Code Injection

The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on the underlying host. Users can restore plugin's configuration by uploading a backup .ini file in the section "Tool > Import/Export". However, the plugin attempts to unserialize values of the .ini file. Moreover, the plugin embeds Monolog library which can be used to craft a gadget chain and thus trigger system command execution.
Mögliche Gegenmaßnahme
All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights): Update to version 4.1.0.2, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AioseoAll In One Seo SwPlatformwordpress Version < 4.1.0.2
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
Version [*, 4.1.0.2)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 53.27% 0.988
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://aioseo.com/changelog/
Vendor Advisory
Release Notes
https://wpscan.com/vulnerability/ab2c94d2-f6c4-418b-bd14-711ed164bcf1
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/b2a98c69-5f76-41f4-8a12-0523285647fb
Third Party Advisory