Cross-site scripting in sickrage
Moderate severity
GitHub Reviewed
Published
Apr 20, 2021
to the GitHub Advisory Database
•
Updated Oct 22, 2024
Description
Published by the National Vulnerability Database
Apr 12, 2021
Reviewed
Apr 13, 2021
Published to the GitHub Advisory Database
Apr 20, 2021
Last updated
Oct 22, 2024
In SiCKRAGE, versions 9.3.54.dev1 to 10.0.11.dev1 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly in the
quicksearch
feature. Therefore, an attacker can steal a user's sessionID to masquerade as a victim user, to carry out any actions in the context of the user.References