CVE-2017-1000237: Scilico I, Librarian

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset any user's password.

Affected products

  • Scilico I, Librarian: up to and including 4.6; version 4.7 only

Published 2017-11-17. Last modified 2026-06-17.