CRITICAL9.8
GHSA-m3xv-x3ph-mq22
Server-side Template Injection in nystudio107/craft-seomatic
Quick fix
GHSA-m3xv-x3ph-mq22 — nystudio107/craft-seomatic: upgrade to the fixed version with the command below.
composer require nystudio107/craft-seomatic:^3.4.12Details
A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic prior to 3.4.12 in src/helpers/UrlHelper.php via the host header.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/nystudio107/craft-seomatic
Introduced in:
0Fixed in: 3.4.12Fix
composer require nystudio107/craft-seomatic:^3.4.12