Chyrp Lite version 2016.04 is vulnerable to a CSRF in the user settings function allowing attackers to hijack the authentication of logged in users to modify account information, including their password.
References
Link | Resource |
---|---|
https://github.com/xenocrat/chyrp-lite/commit/79bb2de7f57d163d256b6bdb127dc09cfdb6235a | Third Party Advisory |
Configurations
Information
Published : 2017-07-17 06:18
Updated : 2017-08-07 11:41
NVD link : CVE-2017-1000008
Mitre link : CVE-2017-1000008
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
chyrp-lite_project
- chyrp_lite