PT-2020-13270 · Craft Cms · Seomatic
Published
2020-05-11
·
Updated
2022-05-24
·
CVE-2020-12790
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SEOmatic plugin versions prior to 3.2.49 for Craft CMS
Description
The issue arises from improper sanitization of the URL in the helpers/DynamicMeta.php file, leading to Server-Side Template Injection. This can result in credentials disclosure via a crafted Twig template after a semicolon.
Recommendations
For versions prior to 3.2.49, update to version 3.2.49 or later to resolve the issue.
Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seomatic