CRITICAL9.8
GHSA-g7xr-v82w-qggq
Code Injection in SEOmatic
Quick fix
GHSA-g7xr-v82w-qggq — nystudio107/craft-seomatic: upgrade to the fixed version with the command below.
composer require nystudio107/craft-seomatic:^3.4.11Details
In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/nystudio107/craft-seomatic
Introduced in:
0Fixed in: 3.4.11Fix
composer require nystudio107/craft-seomatic:^3.4.11