CVE-2017-10711: Simplerisk
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
In SimpleRisk 20170614-001, a CSRF attack on reset.php (aka the Send Password Reset Email form) can insert XSS sequences via the user parameter.
Affected products
- Simplerisk Simplerisk: version 20170614-001 only
Published 2017-07-24. Last modified 2026-06-17.