Discovered by Jack Misiura on behalf of The Missing Link Security
A Server-side Template Injection (SSTI) vulnerability in the CraftCMS Seomatic 3.4.11 and previous plugin by Nystudio107 allows injection of malicious server-side templates through manipulation of the request's host header. Successful exploitation of the issue may allow an unauthenticated attacker to execute arbitrary code on the web application's server.
Discovered in 3.4.10
Fixed in 3.4.12