Описание
In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution.
Ссылки
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.4.11 (включая)
cpe:2.3:a:nystudio107:seomatic:*:*:*:*:*:craft_cms:*:*
EPSS
Процентиль: 99%
0.85815
Высокий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-94
Связанные уязвимости
EPSS
Процентиль: 99%
0.85815
Высокий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-94