PT-2025-3012 · Sickchill · Sickchill
Sylwia Budzynska
+1
·
Published
2025-01-08
·
Updated
2025-11-29
·
CVE-2024-53995
CVSS v4.0
4.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
SickChill versions prior to commit c7128a8946c3701df95c285810eb75b2de18bf82
Description
The issue concerns an open redirect in the login endpoint of SickChill, an automatic video library manager for TV shows. A user-controlled
login endpoint's next parameter takes arbitrary content, allowing an authenticated attacker to redirect the user to arbitrary destinations. This is possible because the login page redirects to the next parameter. The commit c7128a8946c3701df95c285810eb75b2de18bf82 changes this behavior, redirecting instead to settings.DEFAULT PAGE.Recommendations
For versions prior to commit c7128a8946c3701df95c285810eb75b2de18bf82, update to a version that includes the commit c7128a8946c3701df95c285810eb75b2de18bf82 to resolve the issue. As a temporary workaround, consider restricting access to the
login endpoint or disabling the next parameter to minimize the risk of exploitation.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sickchill