VDB
Sign up
CRITICAL9.8

GHSA-m3xv-x3ph-mq22

Server-side Template Injection in nystudio107/craft-seomatic

Quick fix

GHSA-m3xv-x3ph-mq22 — nystudio107/craft-seomatic: upgrade to the fixed version with the command below.

composer require nystudio107/craft-seomatic:^3.4.12

Details

A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic prior to 3.4.12 in src/helpers/UrlHelper.php via the host header.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/nystudio107/craft-seomatic
Introduced in: 0Fixed in: 3.4.12
Fixcomposer require nystudio107/craft-seomatic:^3.4.12

References