#VU99749 Code Injection in All-in-One WP Migration - CVE-2024-9162
Published: November 5, 2024 / Updated: December 27, 2024
All-in-One WP Migration
ServMask
Description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to missing file type validation during the export. A remote administrator can send a specially crafted request and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d97c3379-56c9-4261-9a70-3119ec121a40?source=cve
- https://plugins.trac.wordpress.org/browser/all-in-one-wp-migration/trunk/lib/controller/class-ai1wm-backups-controller.php#L60
- https://plugins.trac.wordpress.org/browser/all-in-one-wp-migration/trunk/lib/controller/class-ai1wm-export-controller.php#L36
- https://github.com/d0n601/CVE-2024-9162
- https://ryankozak.com/posts/CVE-2024-9162