PT-2026-45552 · Sourcecodester · Seo Meta Tag Extractor
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SourceCodester SEO Meta Tag Extractor version 1.0
Description
An issue exists in the
/index.php file where the get headers() function does not properly validate the url argument. This allows a remote attacker to perform Server-Side Request Forgery (SSRF), a technique where the server is tricked into making unauthorized requests to internal or external resources.Recommendations
Update SourceCodester SEO Meta Tag Extractor version 1.0 to a version that contains a fix, or restrict the use of the
url argument in the /index.php file to prevent unauthorized requests.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seo Meta Tag Extractor