Vulnerability Description
Cygnux sysPass version 2.1.7 and older is vulnerable to a Local File Inclusion in the functionality of javascript files inclusion. The attacker can read the configuration files that contain the login and password from the database, private encryption key, as well as other sensitive information.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cygnux | Syspass | <= 2.1.7 |
References
- https://github.com/nuxsmin/sysPass/releases/tag/2.1.8.17042901Release NotesThird Party Advisory
- https://github.com/nuxsmin/sysPass/releases/tag/2.1.8.17042901Release NotesThird Party Advisory
FAQ
What is CVE-2017-1000192?
CVE-2017-1000192 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Cygnux sysPass version 2.1.7 and older is vulnerable to a Local File Inclusion in the functionality of javascript files inclusion. The attacker can read the configuration files that contain the login ...
How severe is CVE-2017-1000192?
CVE-2017-1000192 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-1000192?
Check the references section above for vendor advisories and patch information. Affected products include: Cygnux Syspass.