CVE-2018-14716
high · 7.5A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.
7.5
CVSS
33.0%
EPSS (exploit prob.)
98th
EPSS percentile
2018-08-06
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| nystudio107 | seomatic | < 3.1.4 |
Check a specific version with /api/v1/cve/match.
References
- http://ha.cker.info/exploitation-of-server-side-template-injection-with-craft-cms-plguin-seomatic/
- https://github.com/nystudio107/craft-seomatic/commit/1e7d1d084ac3a89e7ec70620f2749110508d1ce1
- https://github.com/nystudio107/craft-seomatic/releases/tag/3.1.4
- https://twitter.com/nystudio107/status/1021847835418009605
- https://twitter.com/nystudio107/status/1021855169515057152
- https://www.exploit-db.com/exploits/45108/
- http://ha.cker.info/exploitation-of-server-side-template-injection-with-craft-cms-plguin-seomatic/
- https://github.com/nystudio107/craft-seomatic/commit/1e7d1d084ac3a89e7ec70620f2749110508d1ce1
- https://github.com/nystudio107/craft-seomatic/releases/tag/3.1.4
- https://twitter.com/nystudio107/status/1021847835418009605
- https://twitter.com/nystudio107/status/1021855169515057152
- https://www.exploit-db.com/exploits/45108/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-14716