CVE-2018-14716

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
06/08/2018
Last modified:
24/08/2020

Description

A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nystudio107:seomatic:*:*:*:*:*:craft_cms:*:* 3.1.4 (excluding)