First published: Wed Apr 28 2021(Updated: )
The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yoast Yoast Seo | <7.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31779 is a vulnerability in the yoast_seo extension before 7.2.1 for TYPO3 that allows SSRF via a backend user account.
The severity of CVE-2021-31779 is medium with a CVSS score of 6.4.
CVE-2021-31779 affects TYPO3 if the yoast_seo extension before 7.2.1 is installed.
Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to make requests to internal resources accessible from the server.
To fix CVE-2021-31779, update the yoast_seo extension to version 7.2.1 or newer.