Cross-site scripting in SiCKRAGE
Moderate severity
GitHub Reviewed
Published
Apr 20, 2021
to the GitHub Advisory Database
•
Updated Oct 25, 2024
Description
Published by the National Vulnerability Database
Apr 12, 2021
Reviewed
Apr 13, 2021
Published to the GitHub Advisory Database
Apr 20, 2021
Last updated
Oct 25, 2024
in SiCKRAGE, versions 4.2.0 to 10.0.11.dev1 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly when processed by the server. Therefore, an attacker can inject arbitrary JavaScript code inside the application, and possibly steal a user’s sensitive information.
References