S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0692 Scanner

Detects 'Open Redirect' vulnerability in rudloff/alltube affects v. prior to 3.0.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0692
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
rudloff/alltubeby rudloff
AFFECTED< 3.0.1SAFE ✓≥ 3.0.1
Updated Aug 22, 2026View on NVD →
Detail

The rudloff/alltube is an open-source web application designed to allow users to access multimedia content from various sources in one unified interface. The platform boasts an easy-to-use interface and supports a variety of protocols, including HTTP, HTTPS, and BitTorrent. It is primarily aimed at users who want to watch videos and listen to music without ads, and it can be run on a personal server or online via access to the public website.

The CVE-2022-0692 vulnerability detected in rudloff/alltube prior to version 3.0.1 allowed for an open redirect on the website. This flaw could be leveraged by an attacker to direct users to malicious websites without their knowledge. The vulnerabilty was caused by a lack of input sanitization when processing a URL parameter, which could be modified to point to an attacker-controlled website. Exploiting the vulnerability requires convincing the victim to follow a specially-crafted link.

If the vulnerability is exploited, an attacker can redirect users to phishing websites, or websites that host malware or unwanted content. The user may be tricked into revealing sensitive information, such as login credentials or financial data. Additionally, the user may be subjected to ads, pop-ups, and automatic downloads that could compromise their device.

In conclusion, it is essential to stay vigilant and take proactive measures to safeguard digital assets against threats like the one described above. Thanks to the pro features of the s4e.io platform, users can be better equipped to detect, mitigate and manage vulnerabilities in their systems, websites, and applications. By using the platform, users can easily and quickly learn about potential risks associated with their digital assets and take appropriate action before it's too late.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users are advised to upgrade their version of rudloff/alltube to 3.0.1 or later. Additionally, the following best practices can be implemented:

  • Do not click on links from untrusted sources or emails 
  • Use an adblocker and/or pop-up blocker
  • Keep your device and software up-to-date with the latest releases and security patches
  • Enable two-factor authentication where possible 
  • Use a VPN to encrypt your internet traffic and protect your privacy.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.