CVE-2017-10711: Simplerisk

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

In SimpleRisk 20170614-001, a CSRF attack on reset.php (aka the Send Password Reset Email form) can insert XSS sequences via the user parameter.

Affected products

Published 2017-07-24. Last modified 2026-06-17.