Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS13NzQ1LXhqcXgtN3dwOM4AA0TC

Artesãos SEOTools Open Redirect vulnerability

A vulnerability has been found in Artesãos SEOTools up to and including version 0.17.1. This vulnerability affects the function setTitle of the file SEOMeta.php. The manipulation of the argument title leads to open redirect. Upgrading to version 0.17.2 is able to address this issue. The name of the patch is ca27cd0edf917e0bc805227013859b8b5a1f01fb. It is recommended to upgrade the affected component.

Permalink: https://github.com/advisories/GHSA-w745-xjqx-7wp8
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13NzQ1LXhqcXgtN3dwOM4AA0TC
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 1 year ago
Updated: over 1 year ago


CVSS Score: 6.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS Percentage: 0.00188
EPSS Percentile: 0.56623

Identifiers: GHSA-w745-xjqx-7wp8, CVE-2020-36664
References: Repository: https://github.com/artesaos/seotools
Blast Radius: 17.6

Affected Packages

packagist:artesaos/seotools
Dependent packages: 58
Dependent repositories: 779
Downloads: 3,701,062 total
Affected Version Ranges: < 0.17.2
Fixed in: 0.17.2
All affected versions: 0.4.1, 0.7.1, 0.7.2, 0.7.3, 0.7.4, 0.8.0, 0.8.1, 0.8.2, 0.9.0, 0.9.1, 0.9.2, 0.10.0, 0.11.1, 0.12.0, 0.12.1, 0.12.2, 0.13.0, 0.14.0, 0.15.0, 0.16.0, 0.17.0, 0.17.1
All unaffected versions: 0.17.2, 0.18.0, 0.19.0, 0.19.1, 0.20.0, 0.20.1, 0.20.2, 0.21.0, 0.22.0, 0.22.1, 0.23.0, 1.0.0, 1.1.0, 1.2.0, 1.3.0, 1.3.1