PT-2020-20739 · Seomatic · Seomatic

Published

2020-03-04

·

Updated

2022-05-24

·

CVE-2020-9757

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SEOmatic versions prior to 3.3.0 SEOmatic versions prior to 3.2.46
Description The issue allows Server-Side Template Injection that can lead to Remote Code Execution (RCE) via malformed data sent to the metacontainers controller. This can also result in information disclosure. The exploitation occurs through sending specifically crafted data to the metacontainers controller, which is vulnerable to Server-Side Template Injection.
Recommendations For versions prior to 3.3.0, update to version 3.3.0 or later. For versions prior to 3.2.46, update to version 3.2.46 or later. As a temporary workaround, consider restricting access to the metacontainers controller until a patch is applied.

Exploit

Fix

RCE

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9757
GHSA-6Q4J-8PJM-5MGC

Affected Products

Seomatic