midgetspy Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with midgetspy products.
Products
- Sickbeard2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-37027CRITICAL | Sickbeard 0.1 - Remote Command InjectionSickbeard alpha contains a remote command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands through the extra scripts configuration. Attackers can set malicious commands in the extra scripts field and trigger processing to execute remote code on the vulnerable Sickbeard installation. CWE-78Jan 30, 2026 | CVSS9.3v4.0 | EPSS2.26% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37026MEDIUM | Sickbeard 0.1 - Cross-Site Request ForgerySickbeard alpha contains a cross-site request forgery vulnerability that allows attackers to disable authentication by submitting crafted configuration parameters. Attackers can trick users into submitting a malicious form that clears web username and password, effectively removing authentication protection. CWE-352Jan 30, 2026 | CVSS5.1v4.0 | EPSS0.175% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |