Vulnerability Description
A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php via the host header.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nystudio107 | Seomatic | 3.4.12 |
Related Weaknesses (CWE)
References
- https://github.com/nystudio107/craft-seomatic/commit/0c5c0c0e0cb61000d12ec55ebf1PatchThird Party Advisory
- https://github.com/nystudio107/craft-seomatic/releases/tag/3.4.12Release NotesThird Party Advisory
- https://github.com/nystudio107/craft-seomatic/commit/0c5c0c0e0cb61000d12ec55ebf1PatchThird Party Advisory
- https://github.com/nystudio107/craft-seomatic/releases/tag/3.4.12Release NotesThird Party Advisory
FAQ
What is CVE-2021-44618?
CVE-2021-44618 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php via the host header.
How severe is CVE-2021-44618?
CVE-2021-44618 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-44618?
Check the references section above for vendor advisories and patch information. Affected products include: Nystudio107 Seomatic.