CVE-2017-1000192
Last modified
CVE-2017-1000192 is a vulnerability of currently unknown severity. Cygnux sysPass version 2.1.7 and older is vulnerable to a Local File Inclusion in the functionality of javascript files inclusion. The attacker can read the configuration files that contain the login and password from the database, private encryption key, as well as other sensitive information.. EPSS estimates a 0.89% chance of exploitation in the next 30 days.
Description
Cygnux sysPass version 2.1.7 and older is vulnerable to a Local File Inclusion in the functionality of javascript files inclusion. The attacker can read the configuration files that contain the login and password from the database, private encryption key, as well as other sensitive information.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cygnux | Syspass | <= 2.1.7 |
References
- https://github.com/nuxsmin/sysPass/releases/tag/2.1.8.17042901Release Notes, Third Party Advisory
- https://github.com/nuxsmin/sysPass/releases/tag/2.1.8.17042901Release Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-1000192?
How severe is CVE-2017-1000192?
How do I fix CVE-2017-1000192?
Are you affected by CVE-2017-1000192?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
