Cross-site Scripting in SEOmatic plugin
Moderate severity
GitHub Reviewed
Published
Jun 13, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jun 12, 2022
Published to the GitHub Advisory Database
Jun 13, 2022
Reviewed
Jun 20, 2022
Last updated
Jan 27, 2023
A cross-site scripting (XSS) vulnerability in the SEOmatic plugin 3.4.10 for Craft CMS 3 allows remote attackers to inject arbitrary web script via a GET to /index.php?action=seomatic/file/seo-file-link with url parameter containing the base64 encoded URL of a malicious web page / file and fileName parameter containing an arbitrary filename with the intended content-type to be rendered in the user's browser as the extension.
References