sickrage
PyPI3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting sickragepage 1 of 1
- CVE-2018-9160CRITICALCVSS 9.8EG 9.8fixed in 2018.03.09-1 or 9.3.2, by version range2018-03-31
vulnerable: 6.0.47 ... 9.2.99 (314 versions)
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
- CVE-2021-25925MEDIUMCVSS 5.4EG 5.4fixed in 10.0.11.dev2 or 10.0.12.dev1, by version range2021-04-12
vulnerable: 10.0.0 ... 9.4.99 (1095 versions)
in SiCKRAGE, versions 4.2.0 to 10.0.11.dev1 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly when processed by the server. Therefore, an attacker can inject arbitrary JavaScript code inside…
- CVE-2021-25926MEDIUMCVSS 6.1EG 6.1fixed in 10.0.11.dev2 or 10.0.12.dev1, by version range2021-04-12
vulnerable: 10.0.0 ... 9.4.99 (701 versions)
In SiCKRAGE, versions 9.3.54.dev1 to 10.0.11.dev1 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly in the `quicksearch` feature. Therefore, an attacker can steal a user's sessionID to ma…
Check whether sickrage is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for sickrage CVEs against the assets you own.
Book a Demo →