Vulnerability Description
Chyrp Lite version 2016.04 is vulnerable to a CSRF in the user settings function allowing attackers to hijack the authentication of logged in users to modify account information, including their password.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chyrp-Lite Project | Chyrp Lite | 2016.04 |
Related Weaknesses (CWE)
References
- https://github.com/xenocrat/chyrp-lite/commit/79bb2de7f57d163d256b6bdb127dc09cfdThird Party Advisory
- https://github.com/xenocrat/chyrp-lite/commit/79bb2de7f57d163d256b6bdb127dc09cfdThird Party Advisory
FAQ
What is CVE-2017-1000008?
CVE-2017-1000008 is a vulnerability with a CVSS score of 8.8 (HIGH). Chyrp Lite version 2016.04 is vulnerable to a CSRF in the user settings function allowing attackers to hijack the authentication of logged in users to modify account information, including their passw...
How severe is CVE-2017-1000008?
CVE-2017-1000008 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-1000008?
Check the references section above for vendor advisories and patch information. Affected products include: Chyrp-Lite Project Chyrp Lite.