SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-14716

A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.

HIGH 7.5EPSS 33.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 33.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
33.03% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-94
Affected
nystudio107/seomatic
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.