Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS13Mng1LWhwbWctajk4aM4AA0TD

Artesãos SEOTools Open Redirect vulnerability

A vulnerability was found in Artesãos SEOTools up to and including version 0.17.1. This issue affects the function eachValue of the file TwitterCards.php. The manipulation of the argument value leads to open redirect. Upgrading to version 0.17.2 is able to address this issue. The name of the patch is ca27cd0edf917e0bc805227013859b8b5a1f01fb. It is recommended to upgrade the affected component. The identifier VDB-222233 was assigned to this vulnerability.

Permalink: https://github.com/advisories/GHSA-w2x5-hpmg-j98h
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13Mng1LWhwbWctajk4aM4AA0TD
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 10 months ago
Updated: 7 months ago


CVSS Score: 6.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Identifiers: GHSA-w2x5-hpmg-j98h, CVE-2020-36665
References: Repository: https://github.com/artesaos/seotools
Blast Radius: 17.6

Affected Packages

packagist:artesaos/seotools
Dependent packages: 53
Dependent repositories: 779
Downloads: 3,253,222 total
Affected Version Ranges: < 0.17.2
Fixed in: 0.17.2
All affected versions: 0.4.1, 0.7.1, 0.7.2, 0.7.3, 0.7.4, 0.8.0, 0.8.1, 0.8.2, 0.9.0, 0.9.1, 0.9.2, 0.10.0, 0.11.1, 0.12.0, 0.12.1, 0.12.2, 0.13.0, 0.14.0, 0.15.0, 0.16.0, 0.17.0, 0.17.1
All unaffected versions: 0.17.2, 0.18.0, 0.19.0, 0.19.1, 0.20.0, 0.20.1, 0.20.2, 0.21.0, 0.22.0, 0.22.1, 0.23.0, 1.0.0, 1.1.0, 1.2.0, 1.3.0