VDB
Sign up
HIGH7.5

GHSA-6j9m-rp7m-3gfg

SEOmatic plugin for Craft CMS SSTI Vulnerability

Quick fix

GHSA-6j9m-rp7m-3gfg — nystudio107/craft-seomatic: upgrade to the fixed version with the command below.

composer require nystudio107/craft-seomatic:^3.1.4

Details

A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/nystudio107/craft-seomatic
Introduced in: 0Fixed in: 3.1.4
Fixcomposer require nystudio107/craft-seomatic:^3.1.4

References