A cross-site scripting (XSS) vulnerability in the SEOmatic plugin 3.4.10 for Craft CMS 3 allows remote attackers to inject arbitrary web script via a GET to /index.php?action=seomatic/file/seo-file-link with url parameter containing the base64 encoded URL of a malicious web page / file and fileName parameter containing an arbitrary filename with the intended content-type to be rendered in the user's browser as the extension.
{ "nvd_published_at": "2022-06-12T12:15:00Z", "github_reviewed_at": "2022-06-20T22:38:22Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-79" ] }