CVE-2024-53995 - CVE House
Back to Database
Status published Low CVE-2024-53995

GHSL-2024-288: SickChill open redirect in login

Vulnerability Description

SickChill is an automatic video library manager for TV shows. A user-controlled `login` endpoint's `next_` parameter takes arbitrary content. Prior to commit c7128a8946c3701df95c285810eb75b2de18bf82, an authenticated attacker may use this to redirect the user to arbitrary destinations, leading to open redirect. Commit c7128a8946c3701df95c285810eb75b2de18bf82 changes the login page to redirect to `settings.DEFAULT_PAGE` instead of to the `next` parameter.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-53995

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

sickchill
Vulnerable Versions:
<= 2024.3.1

Timeline

Official Publish: January 8th, 2025
Last Modified: February 12th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)