CVE-2021-25037
Summary
| CVE | CVE-2021-25037 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-17 13:15:00 UTC |
| Updated | 2022-01-24 15:12:00 UTC |
| Description | The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discovered during an internal audit by the Jetpack Scan team, and could grant attackers access to privileged information from the affected site’s database (e.g., usernames and hashed passwords). |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Aioseo | All In One Seo | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| All In One SEO < 4.1.5.3 - Authenticated SQL Injection WordPress Security Vulnerability | MISC | wpscan.com | |
| Severe Vulnerabilities Fixed in All In One SEO Plugin Version 4.1.5.3 | MISC | jetpack.com | |
| 403 Forbidden | CONFIRM | plugins.trac.wordpress.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Marc Montpas (Jetpack Scan)
Legacy QID Mappings
- 150474 WordPress All In One SEO Plugin Multiple Vulnerabilities (CVE-2021-25036,CVE-2021-25037)