CVE-2017-8916

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
31/01/2018
Last modified:
24/02/2018

Description

In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisecurity:cis-cat_pro_dashboard:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:cisecurity:cis-cat_pro_dashboard:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cisecurity:cis-cat_pro_dashboard:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:cisecurity:cis-cat_pro_dashboard:1.0.3:*:*:*:*:*:*:*