Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS13NzQ1LXhqcXgtN3dwOM4AA0TC
Artesãos SEOTools Open Redirect vulnerability
A vulnerability has been found in Artesãos SEOTools up to and including version 0.17.1. This vulnerability affects the function setTitle of the file SEOMeta.php. The manipulation of the argument title leads to open redirect. Upgrading to version 0.17.2 is able to address this issue. The name of the patch is ca27cd0edf917e0bc805227013859b8b5a1f01fb. It is recommended to upgrade the affected component.
Permalink: https://github.com/advisories/GHSA-w745-xjqx-7wp8JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13NzQ1LXhqcXgtN3dwOM4AA0TC
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 1 year ago
Updated: over 1 year ago
CVSS Score: 6.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Percentage: 0.00188
EPSS Percentile: 0.56623
Identifiers: GHSA-w745-xjqx-7wp8, CVE-2020-36664
References:
- https://nvd.nist.gov/vuln/detail/CVE-2020-36664
- https://github.com/artesaos/seotools/pull/201
- https://github.com/artesaos/seotools/commit/ca27cd0edf917e0bc805227013859b8b5a1f01fb
- https://github.com/artesaos/seotools/releases/tag/v0.17.2
- https://vuldb.com/?ctiid.222232
- https://vuldb.com/?id.222232
- https://github.com/advisories/GHSA-w745-xjqx-7wp8
Blast Radius: 17.6
Affected Packages
packagist:artesaos/seotools
Dependent packages: 58Dependent repositories: 779
Downloads: 3,701,062 total
Affected Version Ranges: < 0.17.2
Fixed in: 0.17.2
All affected versions: 0.4.1, 0.7.1, 0.7.2, 0.7.3, 0.7.4, 0.8.0, 0.8.1, 0.8.2, 0.9.0, 0.9.1, 0.9.2, 0.10.0, 0.11.1, 0.12.0, 0.12.1, 0.12.2, 0.13.0, 0.14.0, 0.15.0, 0.16.0, 0.17.0, 0.17.1
All unaffected versions: 0.17.2, 0.18.0, 0.19.0, 0.19.1, 0.20.0, 0.20.1, 0.20.2, 0.21.0, 0.22.0, 0.22.1, 0.23.0, 1.0.0, 1.1.0, 1.2.0, 1.3.0, 1.3.1