vendor:
Sickbeard
by:
bdrake
5.5
CVSS
MEDIUM
Cross-Site Request Forgery
352
CWE
Product Name: Sickbeard
Affected Version From: 0.1
Affected Version To: 0.1
Patch Exists: NO
Related CWE:
CPE: a:sickbeard_project:sickbeard:0.1
Platforms Tested: Fedora 32
2020
Sickbeard 0.1 – Cross-Site Request Forgery (Disable Authentication)
This exploit allows an attacker to disable authentication in Sickbeard 0.1 by sending a crafted request. By clearing the username and password fields in the form, authentication can be bypassed. The changes take effect after a server restart.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of Sickbeard or apply the vendor's recommended configuration settings to enforce authentication.