Unrated severityNVD Advisory· Published Jan 31, 2018· Updated Aug 5, 2024
CVE-2017-8916
CVE-2017-8916
Description
In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.
Affected products
1- Range: <1.0.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.cisecurity.org/cis-security-updates/incorrect-access-control-cve-2017-8916/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.