← Back

CVE-2017-8916

nvd nist
Published: Jan 31, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.

Affected (4)

1 product
Cis Cat Pro Dashboard
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Cisecurity
Version 1.0.0
Version 1.0.1
Version 1.0.2
Version 1.0.3

Timeline

No history available yet.