CVE-2018-14716
SEOmatic plugin for Craft CMS SSTI Vulnerability
7.5
HIGH
CVSS 3.1
EPSS 33.0%
Description
A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.
How to fix CVE-2018-14716
To remediate CVE-2018-14716, upgrade the affected package to a fixed version below.
- Packagist/nystudio107/craft-seomatic—upgrade to 3.1.4 or later
Is CVE-2018-14716 being exploited?
Moderate — EPSS is 33.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 3.1.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |