VDB
Sign up
CRITICAL9.8

GHSA-g7xr-v82w-qggq

Code Injection in SEOmatic

Quick fix

GHSA-g7xr-v82w-qggq — nystudio107/craft-seomatic: upgrade to the fixed version with the command below.

composer require nystudio107/craft-seomatic:^3.4.11

Details

In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/nystudio107/craft-seomatic
Introduced in: 0Fixed in: 3.4.11
Fixcomposer require nystudio107/craft-seomatic:^3.4.11

References