Record summary

CVE-2020-9757 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 19, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
GitHub AdvisoryBefore 3.3.0 · Fixed in 3.3.0affected

Nuclei templates

1
ProjectDiscoveryCRITICALCraft CMS < 3.3.0 - Server-Side Template InjectionCVSS 9.8

Craft CMS before 3.3.0 is susceptible to server-side template injection via the SEOmatic component that could lead to remote code execution via malformed data submitted to the metacontainers controller.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the server.

Remediation

Upgrade Craft CMS to version 3.3.0 or higher to mitigate this vulnerability.

WeaknessesCWE-74
Authorsdwisiswant0
Template tagscvecve2020ssticraftcmsvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:craftcms:craft_cms"
Shodan: http.html:craftcms
Shodan: http.favicon.hash:-47932290
FOFA: icon_hash=-47932290
FOFA: body=craftcms

Source: ProjectDiscovery

References

6