Description
Rapid7 Nexpose versions 6.6.93 and earlier are susceptible to an SQL Injection vulnerability, whereby valid search operators are not defined. This lack of validation can allow a logged-in, authenticated attacker to manipulate the "ANY" and "OR" operators in the SearchCriteria and inject SQL code. This issue was fixed in Rapid7 Nexpose version 6.6.129.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-15820 | Rapid7 Nexpose versions 6.6.93 and earlier are susceptible to an SQL Injection vulnerability, whereby valid search operators are not defined. This lack of validation can allow a logged-in, authenticated attacker to manipulate the "ANY" and "OR" operators in the SearchCriteria and inject SQL code. This issue was fixed in Rapid7 Nexpose version 6.6.129. |
References
| Link | Providers |
|---|---|
| https://docs.rapid7.com/release-notes/nexpose/20220302/ |
|
History
No history.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2024-09-16T17:48:14.153Z
Reserved: 2022-02-24T00:00:00.000Z
Link: CVE-2022-0757
No data.
Status : Modified
Published: 2022-03-17T23:15:07.610
Modified: 2024-11-21T06:39:20.110
Link: CVE-2022-0757
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD