CVE-2021-41750
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A cross-site scripting (XSS) vulnerability in the SEOmatic plugin 3.4.10 for Craft CMS 3 allows remote attackers to inject arbitrary web script via a GET to /index.php?action=seomatic/file/seo-file-link with url parameter containing the base64 encoded URL of a malicious web page / file and fileName parameter containing an arbitrary filename with the intended content-type to be rendered in the user's browser as the extension.
Una vulnerabilidad de tipo cross-site scripting (XSS) en el plugin SEOmatic 3.4.10 para Craft CMS 3 permite a atacantes remotos inyectar un script web arbitrario por medio de un GET a /index.php?action=seomatic/file/seo-file-link con el parámetro url que contiene la URL codificada en base64 de una página web/archivo maliciosa y el parámetro fileName que contiene un nombre de archivo arbitrario con el tipo de contenido previsto para ser renderizado en el navegador del usuario como la extensión
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-09-27 CVE Reserved
- 2022-06-12 CVE Published
- 2024-08-04 CVE Updated
- 2025-01-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/nystudio107/craft-seomatic/blob/develop/CHANGELOG.md | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nystudio107 Search vendor "Nystudio107" | Seomatic Search vendor "Nystudio107" for product "Seomatic" | 3.4.10 Search vendor "Nystudio107" for product "Seomatic" and version "3.4.10" | craft_cms |
Affected
|