CVE-2020-9757

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
04/03/2020
Last modified:
26/04/2022

Description

The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* 3.3.0 (excluding)