github.com
https://github.com/giany/CVE/blob/master/CVE-2020-9757.txt CVE-2020-9757
CRITICALNuclei
SEOmatic for CraftCMS allows Server-Side Template Injection
Record summary
CVE-2020-9757 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 19, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Craft CMSBrowse craftcms / Craft CMS | VulnCheck | Version data not supplied | |
nystudio107/craft-seomaticBrowse Packagist / nystudio107/craft-seomatic | GitHub Advisory | Before 3.3.0 · Fixed in 3.3.0 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALCraft CMS < 3.3.0 - Server-Side Template InjectionCVSS 9.8
Craft CMS before 3.3.0 is susceptible to server-side template injection via the SEOmatic component that could lead to remote code execution via malformed data submitted to the metacontainers controller.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the server.
Remediation
Upgrade Craft CMS to version 3.3.0 or higher to mitigate this vulnerability.
WeaknessesCWE-74
Authorsdwisiswant0
Template tagscvecve2020ssticraftcmsvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:craftcms:craft_cms"
Shodan: http.html:craftcms
Shodan: http.favicon.hash:-47932290
FOFA: icon_hash=-47932290
FOFA: body=craftcms
https://github.com/nystudio107/craft-seomatic/blob/v3/CHANGELOG.md https://github.com/giany/CVE/blob/master/CVE-2020-9757.txt https://github.com/nystudio107/craft-seomatic/commit/65ab659cb6c914c7ad671af1e417c0da2431f79b https://github.com/nystudio107/craft-seomatic/commit/a1c2cad7e126132d2442ec8ec8e9ab43df02cc0f https://nvd.nist.gov/vuln/detail/CVE-2020-9757
Source: ProjectDiscovery
References
6github.com
https://github.com/nystudio107/craft-seomatic github.com
https://github.com/nystudio107/craft-seomatic/blob/v3/CHANGELOG.md github.comConfirmation
https://github.com/nystudio107/craft-seomatic/commit/65ab659cb6c914c7ad671af1e417c0da2431f79b github.comConfirmation
https://github.com/nystudio107/craft-seomatic/commit/a1c2cad7e126132d2442ec8ec8e9ab43df02cc0f nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-9757