{"id":"CVE-2017-1000008","details":"Chyrp Lite version 2016.04 is vulnerable to a CSRF in the user settings function allowing attackers to hijack the authentication of logged in users to modify account information, including their password.","modified":"2026-07-08T11:48:12.793438Z","published":"2017-07-17T13:18:16.157Z","references":[{"type":"ADVISORY","url":"https://github.com/xenocrat/chyrp-lite/commit/79bb2de7f57d163d256b6bdb127dc09cfdb6235a"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/xenocrat/chyrp-lite","events":[{"introduced":"5fdec05c891d06f5300a8e33ab7cbb18ef7a92a9"},{"last_affected":"5fdec05c891d06f5300a8e33ab7cbb18ef7a92a9"},{"fixed":"79bb2de7f57d163d256b6bdb127dc09cfdb6235a"}],"database_specific":{"cpe":"cpe:2.3:a:chyrp-lite_project:chyrp_lite:2016.04:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2016.04"},{"last_affected":"2016.04"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["2016.04","v2016.04"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1000008.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}