VDB
Sign up
HIGH7.5

GHSA-23q7-59jj-2pj4

SEOmatic for CraftCMS allows Server-Side Template Injection

Quick fix

GHSA-23q7-59jj-2pj4 — nystudio107/craft-seomatic: upgrade to the fixed version with the command below.

composer require nystudio107/craft-seomatic:^3.2.49

Details

In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This leads to Server-Side Template Injection and credentials disclosure via a crafted Twig template after a semicolon.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/nystudio107/craft-seomatic
Introduced in: 0Fixed in: 3.2.49
Fixcomposer require nystudio107/craft-seomatic:^3.2.49

References