6.1

CVE-2020-36664

Exploit

Artesãos SEOTools SEOMeta.php setTitle redirect

A vulnerability has been found in Artesãos SEOTools up to 0.17.1 and classified as problematic. This vulnerability affects the function setTitle of the file SEOMeta.php. The manipulation of the argument title leads to open redirect. Upgrading to version 0.17.2 is able to address this issue. The name of the patch is ca27cd0edf917e0bc805227013859b8b5a1f01fb. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-222232.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Seotool ProjectSeotool SwPlatformlaravel Version < 0.17.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.455
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cna@vuldb.com 5.5 2.1 3.4
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cna@vuldb.com 5.2 5.1 6.4
AV:A/AC:L/Au:S/C:P/I:P/A:P
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

https://github.com/artesaos/seotools/commit/ca27cd0edf917e0bc805227013859b8b5a1f01fb
Patch
https://github.com/artesaos/seotools/pull/201
Patch
Exploit
https://github.com/artesaos/seotools/releases/tag/v0.17.2
Release Notes
https://vuldb.com/?ctiid.222232
Third Party Advisory
VDB Entry
Permissions Required
https://vuldb.com/?id.222232
Third Party Advisory
VDB Entry
Permissions Required