CVE-2017-8916: Cisecurity Cis-Cat Pro Dashboard

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.

Affected products

  • Cisecurity Cis-Cat Pro Dashboard: version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only

Published 2018-01-31. Last modified 2026-06-17.