VYPR
Medium severity6.1NVD Advisory· Published Apr 12, 2021· Updated Jun 17, 2026

CVE-2021-25926

CVE-2021-25926

Description

In SiCKRAGE, versions 9.3.54.dev1 to 10.0.11.dev1 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly in the quicksearch feature. Therefore, an attacker can steal a user's sessionID to masquerade as a victim user, to carry out any actions in the context of the user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
sickragePyPI
>= 9.3.54, < 10.0.11.dev210.0.11.dev2

Affected products

4
  • Sickrage/Sickrage2 versions
    cpe:2.3:a:sickrage:sickrage:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sickrage:sickrage:*:*:*:*:*:*:*:*range: >=9.3.54,<10.0.11
    • cpe:2.3:a:sickrage:sickrage:10.0.11:dev1:*:*:*:*:*:*
  • SiCKRAGE/SiCKRAGEdescription
  • ghsa-coords
    Range: >= 9.3.54, < 10.0.11.dev2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.