
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability has been identified in Artesãos SEOTools up to version 0.17.1, tracked as CVE-2020-36664. The vulnerability affects the setTitle function in SEOMeta.php and is classified as an open redirect vulnerability. The issue was discovered and patched in version 0.17.2, with the fix implemented through commit ca27cd0edf917e0bc805227013859b8b5a1f01fb (GitHub Patch).
The vulnerability is related to insufficient input validation in the setTitle function within SEOMeta.php. The manipulation of the title argument could lead to an open redirect condition. The issue has been assigned a CVSS v3.1 base score of 6.1 (MEDIUM) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (NVD).
If exploited, this vulnerability could allow attackers to perform open redirect attacks, potentially leading to phishing attempts or directing users to malicious websites. The vulnerability affects the confidentiality and integrity of the system with low impact, while availability is not affected (NVD).
The recommended mitigation is to upgrade to Artesãos SEOTools version 0.17.2 or later. The fix involves adding proper input validation by implementing string replacement to remove potentially dangerous URL components (GitHub Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."