Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability - CVE-2020-9757 - Vulnerability Database
Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability - CVE-2020-9757
High
Reference:
CVE-2020-9757
Title:
Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability
Overview:
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.