CVE-2018-14716
Summary
| CVE | CVE-2018-14716 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-06 20:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code. |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nystudio107 | Seomatic | All | All | All | All |
| Application | Nystudio107 | Seomatic | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| nystudio107 na Twitterze: "???? PSA: If you're using SEOmatic for Craft CMS 3, I've been alerted to a potential security vulnerability that will be disclosed in the coming days It's a bit obtuse, but it was fixed in SEOmatic 3.1.4 & later, so please update, just to be safe! #craftcms https://t.co/Hc7iOPzak3… https://t.co/Hu2l433Faz" | CONFIRM | twitter.com | Vendor Advisory |
| Craft CMS SEOmatic plugin 3.1.4 - Server-Side Template Injection - Linux webapps Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Release Version 3.1.4 · nystudio107/craft-seomatic · GitHub | CONFIRM | github.com | Patch, Vendor Advisory |
| nystudio107 na Twitterze: "The researcher in question was awesome, by the way. I'm glad he was responsible and disclosed it to me ahead of time! Here's my response to his article that he wrote up.… https://t.co/UfhZg8NsHH" | CONFIRM | twitter.com | Vendor Advisory |
| Exploitation of Server Side Template Injection with Craft CMS plugin SEOmatic | Can I Haz Security | MISC | ha.cker.info | Third Party Advisory |
| Changed the way requests that don't match any elements generate the `… · nystudio107/craft-seomatic@1e7d1d0 · GitHub | CONFIRM | github.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.