CVE-2023-1699

Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability.  This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.  
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:rapid7:nexpose:*:*:*:*:*:*:*:*

History

07 Nov 2023, 04:04

Type Values Removed Values Added
Summary Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability. This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187. Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability.  This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.  

06 Apr 2023, 17:24

Type Values Removed Values Added
CWE CWE-425
References (MISC) https://docs.rapid7.com/release-notes/nexpose/20230329/ - (MISC) https://docs.rapid7.com/release-notes/nexpose/20230329/ - Release Notes
First Time Rapid7
Rapid7 nexpose
CPE cpe:2.3:a:rapid7:nexpose:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

Information

Published : 2023-03-30 10:15

Updated : 2023-11-07 04:04


NVD link : CVE-2023-1699

Mitre link : CVE-2023-1699


JSON object : View

Products Affected

rapid7

  • nexpose
CWE
CWE-425

Direct Request ('Forced Browsing')