CVE-2017-1000008: Chyrp-Lite Project Chyrp Lite
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Chyrp Lite version 2016.04 is vulnerable to a CSRF in the user settings function allowing attackers to hijack the authentication of logged in users to modify account information, including their password.
Affected products
- Chyrp-Lite Project Chyrp Lite: version 2016.04 only
Published 2017-07-17. Last modified 2026-06-17.