Vulnerability Description
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Craftcms | Craft Cms | < 3.3.0 |
Related Weaknesses (CWE)
References
- https://github.com/giany/CVE/blob/master/CVE-2020-9757.txtExploitThird Party Advisory
- https://github.com/nystudio107/craft-seomatic/blob/v3/CHANGELOG.mdRelease NotesThird Party Advisory
- https://github.com/nystudio107/craft-seomatic/commit/65ab659cb6c914c7ad671af1e41PatchThird Party Advisory
- https://github.com/nystudio107/craft-seomatic/commit/a1c2cad7e126132d2442ec8ec8ePatchThird Party Advisory
- https://github.com/giany/CVE/blob/master/CVE-2020-9757.txtExploitThird Party Advisory
- https://github.com/nystudio107/craft-seomatic/blob/v3/CHANGELOG.mdRelease NotesThird Party Advisory
- https://github.com/nystudio107/craft-seomatic/commit/65ab659cb6c914c7ad671af1e41PatchThird Party Advisory
- https://github.com/nystudio107/craft-seomatic/commit/a1c2cad7e126132d2442ec8ec8ePatchThird Party Advisory
FAQ
What is CVE-2020-9757?
CVE-2020-9757 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.
How severe is CVE-2020-9757?
CVE-2020-9757 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-9757?
Check the references section above for vendor advisories and patch information. Affected products include: Craftcms Craft Cms.