CVE-2020-12790
PHP vulnerability analysis and mitigation

Overview

The SEOmatic plugin before version 3.2.49 for Craft CMS contained a Server-Side Template Injection (SSTI) vulnerability (CVE-2020-12790). The vulnerability was discovered in the helpers/DynamicMeta.php file where improper URL sanitization could lead to template injection and credentials disclosure. The issue was disclosed on March 23, 2020, and affected all versions of the plugin prior to 3.2.49 (ISEC Report).

Technical details

The vulnerability existed due to insufficient sanitization in the helpers/DynamicMeta.php file, where an attacker could inject a Twig template through a URL-part following a semicolon. The injected Twig template would then be rendered in the server response, allowing for Server-Side Template Injection. By leveraging Craft CMS built-in methods, attackers could read information from configuration files, including sensitive database credentials through expressions like craft.config.get('password','db') and craft.config.get('user','db') (ISEC Report).

Impact

The vulnerability allowed attackers to access sensitive information from the application, including database credentials. Through the exploitation of the SSTI vulnerability, attackers could leverage Craft CMS built-in methods to read configuration files and extract sensitive data (ISEC Report).

Exploitability

The vulnerability could be exploited by injecting a Twig template through a URL-part after a semicolon. A proof of concept demonstration was provided by the security researchers who discovered the issue (ISEC Report).

Mitigation and workarounds

The vulnerability was patched in SEOmatic version 3.2.49, released on March 24, 2020. The fix ensures that URLs are properly urldecoded before attempting to use a RegEx to strip tags from them (GitHub Release). Users should upgrade to version 3.2.49 or later to protect against this vulnerability.

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77143HIGH8.8
  • PHP logoPHP
  • composer://jweiland/pforum
NoYesAug 25, 2026
CVE-2026-77142HIGH8.8
  • PHP logoPHP
  • composer://jweiland/yellowpages2
NoYesAug 25, 2026
CVE-2026-77146HIGH8.3
  • PHP logoPHP
  • composer://in2code/femanager
NoYesAug 25, 2026
CVE-2026-77145HIGH7.1
  • PHP logoPHP
  • composer://jweiland/events2
NoYesAug 25, 2026
CVE-2026-77144HIGH7.1
  • PHP logoPHP
  • composer://jweiland/events2
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management