CVE-2017-9673: Simplece

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

In SimpleCE 2.3.0, a CSRF vulnerability can be exploited to add an administrator account (via the index.php/user/new URI) or change its settings (via the index.php/user/1 URI), including its password.

Affected products

  • Simplece Simplece: up to and including 2.3.0

Published 2017-06-15. Last modified 2026-06-17.