PT-2021-15844 · Monolog+1 · Monolog+1

Darkpills

+1

·

Published

2021-05-24

·

Updated

2022-05-03

·

CVE-2021-24307

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings versions prior to 4.1.0.2
Description The issue allows authenticated users with aioseo tools settings privilege, typically admins, to execute arbitrary code on the host. This is possible because the plugin attempts to unserialize values from uploaded .ini files in the "Tool > Import/Export" section. The embedded Monolog library can be exploited to create a gadget chain, leading to system command execution.
Recommendations For versions prior to 4.1.0.2, update to version 4.1.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "Tool > Import/Export" section and the aioseo tools settings privilege to minimize the risk of exploitation. Avoid uploading .ini files from untrusted sources until the issue is resolved.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24307

Affected Products

All In One Seo
Monolog