GHSL-2024-288: SickChill open redirect in login
Low severity
GitHub Reviewed
Published
Jan 8, 2025
to the GitHub Advisory Database
•
Updated Jan 8, 2025
Description
Published by the National Vulnerability Database
Jan 8, 2025
Published to the GitHub Advisory Database
Jan 8, 2025
Reviewed
Jan 8, 2025
Last updated
Jan 8, 2025
SickChill is an automatic video library manager for TV shows. A user-controlled
loginendpoint'snext_parameter takes arbitrary content. Prior to commit c7128a8946c3701df95c285810eb75b2de18bf82, an authenticated attacker may use this to redirect the user to arbitrary destinations, leading to open redirect. Commit c7128a8946c3701df95c285810eb75b2de18bf82 changes the login page to redirect tosettings.DEFAULT_PAGEinstead of to thenextparameter.References