CVE-2023-1699

Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability.  This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.  
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:rapid7:nexpose:*:*:*:*:*:*:*:*

History

07 Nov 2023, 04:04

Type Values Removed Values Added
Summary Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability. This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187. Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability.  This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.  

06 Apr 2023, 17:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References (MISC) https://docs.rapid7.com/release-notes/nexpose/20230329/ - (MISC) https://docs.rapid7.com/release-notes/nexpose/20230329/ - Release Notes
CPE cpe:2.3:a:rapid7:nexpose:*:*:*:*:*:*:*:*
First Time Rapid7 nexpose
Rapid7
CWE CWE-425

30 Mar 2023, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-30 10:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-1699

Mitre link : CVE-2023-1699

CVE.ORG link : CVE-2023-1699


JSON object : View

Products Affected

rapid7

  • nexpose
CWE
CWE-425

Direct Request ('Forced Browsing')