In SimpleRisk 20170614-001, a CSRF attack on reset.php (aka the Send Password Reset Email form) can insert XSS sequences via the user parameter.
{
"source": "CPE_STRING",
"cpe": "cpe:2.3:a:simplerisk:simplerisk:20170614-001:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "20170614-001"
},
{
"last_affected": "20170614-001"
}
]
}