CVE-2017-9673: Simplece
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
In SimpleCE 2.3.0, a CSRF vulnerability can be exploited to add an administrator account (via the index.php/user/new URI) or change its settings (via the index.php/user/1 URI), including its password.
Affected products
- Simplece Simplece: up to and including 2.3.0
Published 2017-06-15. Last modified 2026-06-17.