SickChill's login endpoint's 'next_' parameter accepts arbitrary content, allowing authenticated attackers to perform open redirects, but this was fixed in commit c7128a8946c3701df95c285810eb75b2de18bf82 by redirecting to a default page.
id: CVE-2024-53995
info:
name: SickChill - Open Redirect
author: omarkurt
severity: low
des
...