CVE-2018-14716

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-14716
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-14716.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-14716
Aliases
Published
2018-08-06T20:29:01Z
Modified
2024-05-14T06:20:05.879213Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.

References

Affected packages

Git / github.com/nystudio107/craft-seomatic

Affected ranges

Type
GIT
Repo
https://github.com/nystudio107/craft-seomatic
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

3.*

3.0.0
3.0.0-beta.1
3.0.0-beta.10
3.0.0-beta.11
3.0.0-beta.12
3.0.0-beta.13
3.0.0-beta.14
3.0.0-beta.15
3.0.0-beta.16
3.0.0-beta.17
3.0.0-beta.18
3.0.0-beta.19
3.0.0-beta.2
3.0.0-beta.20
3.0.0-beta.21
3.0.0-beta.22
3.0.0-beta.23
3.0.0-beta.24
3.0.0-beta.3
3.0.0-beta.4
3.0.0-beta.5
3.0.0-beta.6
3.0.0-beta.7
3.0.0-beta.8
3.0.0-beta.9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.20
3.0.22
3.0.23
3.0.24
3.0.25
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.1
3.1.2
3.1.3