github.com
https://github.com/FriendsOfPHP/security-advisories/blob/master/rudloff/alltube/CVE-2022-0692.yaml CVE-2022-0692
MEDIUMNuclei
Open Redirect on Rudloff/alltube in rudloff/alltube
Record summary
CVE-2022-0692 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
rudloff/alltubeBrowse rudloff / rudloff/alltube | CVE List | Before 3.0.1 | affected |
rudloff/alltubeBrowse Packagist / rudloff/alltube | GitHub Advisory | Before 3.0.1 · Fixed in 3.0.1 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMRudloff alltube prior to 3.0.1 - Open RedirectCVSS 6.1
An open redirect vulnerability exists in Rudloff/alltube that could let an attacker construct a URL within the application that causes redirection to an arbitrary external domain via Packagist in versions prior to 3.0.1.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to potential phishing attacks or the download of malware.
Remediation
Upgrade to version 3.0.1 or later to fix the open redirect vulnerability.
WeaknessesCWE-601
Authors0x_Akoko
Template tagscvecve2022huntrredirectrudloffalltubealltube_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:alltube_project:alltube:*:*:*:*:*:*:*:*
https://huntr.dev/bounties/4fb39400-e08b-47af-8c1f-5093c9a51203/ https://nvd.nist.gov/vuln/detail/CVE-2022-0692 https://huntr.dev/bounties/4fb39400-e08b-47af-8c1f-5093c9a51203 https://github.com/rudloff/alltube/commit/bc14b6e45c766c05757fb607ef8d444cbbfba71a https://github.com/ARPSyndicate/cvemon
Source: ProjectDiscovery
References
6github.com
https://github.com/Rudloff/alltube github.com
https://github.com/Rudloff/alltube/security/advisories/GHSA-jmhf-9fj8-88gh github.com
https://github.com/rudloff/alltube/commit/bc14b6e45c766c05757fb607ef8d444cbbfba71a huntr.devConfirmation
https://huntr.dev/bounties/4fb39400-e08b-47af-8c1f-5093c9a51203 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-0692