Vulnerabilities > Cisecurity > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-01-31 CVE-2017-8916 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Cisecurity Cis-Cat PRO Dashboard
In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.
local
low complexity
cisecurity CWE-640
4.6