A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.
References
Configurations
History
21 Nov 2024, 03:49
Type | Values Removed | Values Added |
---|---|---|
References | () http://ha.cker.info/exploitation-of-server-side-template-injection-with-craft-cms-plguin-seomatic/ - Third Party Advisory | |
References | () https://github.com/nystudio107/craft-seomatic/commit/1e7d1d084ac3a89e7ec70620f2749110508d1ce1 - Vendor Advisory | |
References | () https://github.com/nystudio107/craft-seomatic/releases/tag/3.1.4 - Patch, Vendor Advisory | |
References | () https://twitter.com/nystudio107/status/1021847835418009605 - Vendor Advisory | |
References | () https://twitter.com/nystudio107/status/1021855169515057152 - Vendor Advisory | |
References | () https://www.exploit-db.com/exploits/45108/ - Exploit, Third Party Advisory, VDB Entry |
Information
Published : 2018-08-06 20:29
Updated : 2024-11-21 03:49
NVD link : CVE-2018-14716
Mitre link : CVE-2018-14716
CVE.ORG link : CVE-2018-14716
JSON object : View
Products Affected
nystudio107
- seomatic
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')