Record summary

CVE-2022-0692 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListBefore 3.0.1affected
GitHub AdvisoryBefore 3.0.1 · Fixed in 3.0.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMRudloff alltube prior to 3.0.1 - Open RedirectCVSS 6.1

An open redirect vulnerability exists in Rudloff/alltube that could let an attacker construct a URL within the application that causes redirection to an arbitrary external domain via Packagist in versions prior to 3.0.1.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to potential phishing attacks or the download of malware.

Remediation

Upgrade to version 3.0.1 or later to fix the open redirect vulnerability.

WeaknessesCWE-601
Authors0x_Akoko
Template tagscvecve2022huntrredirectrudloffalltubealltube_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:alltube_project:alltube:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

6