vendor:
SEOmatic plugin
by:
Sebastian Kriesten (0xB455)
7.5
CVSS
HIGH
Server-Side Template Injection
94
CWE
Product Name: SEOmatic plugin
Affected Version From: 3.1.2004
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2018-14716
CPE: a:craftcms:craft_seomatic:3.1.4
Platforms Tested:
2018
Craft CMS SEOmatic plugin 3.1.4 – Server-Side Template Injection
An unauthenticated user can trigger the Twig template engine by injecting code into the URI. This can be leveraged to perform arbitrary calls against the template engine and the CMS. The output will be reflected within the Link header of the response.
Mitigation:
Upgrade to a fixed version (version 3.1.5 or later).