CVE-2018-14716
Last modified
CVE-2018-14716 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.. EPSS estimates a 33.03% chance of exploitation in the next 30 days.
Description
A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nystudio107 | Seomatic | < 3.1.4 |
References
- https://github.com/nystudio107/craft-seomatic/releases/tag/3.1.4Patch, Vendor Advisory
- https://twitter.com/nystudio107/status/1021847835418009605Vendor Advisory
- https://twitter.com/nystudio107/status/1021855169515057152Vendor Advisory
- https://www.exploit-db.com/exploits/45108/Exploit, Third Party Advisory, VDB Entry
- https://github.com/nystudio107/craft-seomatic/releases/tag/3.1.4Patch, Vendor Advisory
- https://twitter.com/nystudio107/status/1021847835418009605Vendor Advisory
- https://twitter.com/nystudio107/status/1021855169515057152Vendor Advisory
- https://www.exploit-db.com/exploits/45108/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-14716?
How severe is CVE-2018-14716?
How do I fix CVE-2018-14716?
Are you affected by CVE-2018-14716?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
