CVE-2022-0692 Scanner

Detects 'Open Redirect' vulnerability in rudloff/alltube affects v. prior to 3.0.1.


CVE-2022-0692 Scanner Detail

The rudloff/alltube is an open-source web application designed to allow users to access multimedia content from various sources in one unified interface. The platform boasts an easy-to-use interface and supports a variety of protocols, including HTTP, HTTPS, and BitTorrent. It is primarily aimed at users who want to watch videos and listen to music without ads, and it can be run on a personal server or online via access to the public website.

The CVE-2022-0692 vulnerability detected in rudloff/alltube prior to version 3.0.1 allowed for an open redirect on the website. This flaw could be leveraged by an attacker to direct users to malicious websites without their knowledge. The vulnerabilty was caused by a lack of input sanitization when processing a URL parameter, which could be modified to point to an attacker-controlled website. Exploiting the vulnerability requires convincing the victim to follow a specially-crafted link.

If the vulnerability is exploited, an attacker can redirect users to phishing websites, or websites that host malware or unwanted content. The user may be tricked into revealing sensitive information, such as login credentials or financial data. Additionally, the user may be subjected to ads, pop-ups, and automatic downloads that could compromise their device.

If the vulnerability is exploited, an attacker can redirect users to phishing websites, or websites that host malware or unwanted content. The user may be tricked into revealing sensitive information, such as login credentials or financial data. Additionally, the user may be subjected to ads, pop-ups, and automatic downloads that could compromise their device.



