Code Injection in SEOmatic
Critical severity
GitHub Reviewed
Published
Jun 13, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jun 12, 2022
Published to the GitHub Advisory Database
Jun 13, 2022
Reviewed
Jun 20, 2022
Last updated
Jan 27, 2023
In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution.
References