First published: Wed Mar 04 2020(Updated: )
The Seomatic component before 3.2.46 for Craft CMS allows Server-Side Template Injection and information disclosure via malformed data to the metacontainers controller.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Craftcms Craft Cms | <3.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9757 is a vulnerability in the Seomatic component before version 3.2.46 for Craft CMS that allows Server-Side Template Injection and information disclosure.
CVE-2020-9757 has a severity rating of 9.8 out of 10, which is considered critical.
CVE-2020-9757 allows an attacker to inject malicious code into server-side templates and can lead to unauthorized access and information disclosure.
Yes, updating to version 3.3.0 or later of the Seomatic component for Craft CMS remedies the CVE-2020-9757 vulnerability.
You can find more information about CVE-2020-9757 at the official NIST vulnerability database and the GitHub commits for the Craft CMS Seomatic component.