Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22635
HistoryMar 05, 2020 - 4:28 a.m.

Server-Side Template Injection (SSTI)

2020-03-0504:28:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.962 High

EPSS

Percentile

99.5%

nystudio107/craft-seomatic is vulnerable to server-side template injection. Lack of validation and sanitization allows an attacker to inject and execute arbitrary template variables that can lead to code execution via malicious data to the metacontainers controller.