Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-64vh-qw36-84gx

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.

In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.

EPSS

Процентиль: 16%
0.00049
Низкий

7.8 High

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 7.8
nvd
около 8 лет назад

In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access.

EPSS

Процентиль: 16%
0.00049
Низкий

7.8 High

CVSS3

Дефекты

CWE-640