Sploitus

CVE-2021-24307

2 known exploits for CVE-2021-24307

The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated users with "aioseo_tools_settings" privilege (most of the time admin) to execute arbitrary code on the underlying host. Users can restore plugin's configuration by uploading a backup .ini file in the section "Tool > Import/Export". However, the plugin attempts to unserialize values of the .ini file. Moreover, the plugin embeds Monolog library which can be used to craft a gadget chain and thus trigger system command execution.

Affected products
All In One Seo, Monolog
Aioseo All In One Seo
< 4.1.0.2
Fix
Available
CVSS 2.0
9.0 HIGH
CVSS 3.1
8.8 HIGH
EPSS
53.3% (99th percentile)
Weakness
CWE-502
NVD status
Modified
Published
2021-05-24
CVE-2021-24307 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2021-24307

Proof-of-concept code and exploit modules indexed by Sploitus