vendor:
SickRage
by:
Sven Fassbender
9.8
CVSS
CRITICAL
Clear-Text Credentials
200
CWE
Product Name: SickRage
Affected Version From: < v2018.03.09-1
Affected Version To: < v2018.03.09-1
Patch Exists: YES
Related CWE: CVE-2018-9160
CPE: a:sickrage:sickrage
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
SickRage < v2018.03.09 - Clear-Text Credentials HTTP Response
SickRage returns clear-text credentials for e.g. GitHub, AniDB, Kodi, Plex etc. in HTTP responses. Prerequisite is that the user did not set a username and password for their SickRage installation. (not enforced, default)
Mitigation:
Enforce a username and password for SickRage installation.