Cross-Site Scripting (XSS) Vulnerability in SEOmatic Plugin 3.4.10 for Craft CMS 3

Cross-Site Scripting (XSS) Vulnerability in SEOmatic Plugin 3.4.10 for Craft CMS 3

CVE-2021-41750 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

A cross-site scripting (XSS) vulnerability in the SEOmatic plugin 3.4.10 for Craft CMS 3 allows remote attackers to inject arbitrary web script via a GET to /index.php?action=seomatic/file/seo-file-link with url parameter containing the base64 encoded URL of a malicious web page / file and fileName parameter containing an arbitrary filename with the intended content-type to be rendered in the user's browser as the extension.

Learn more about our Web App Pen Testing.