Description
Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the ‘data/console/redirect’ component of the application. This issue was resolved in the February, 2023 release of version 6.6.179.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12710 | Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the ‘data/console/redirect’ component of the application. This issue was resolved in the February, 2023 release of version 6.6.179. |
References
| Link | Providers |
|---|---|
| https://docs.rapid7.com/release-notes/nexpose/20230208/ |
|
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2025-02-26T18:44:06.211Z
Reserved: 2023-02-06T14:52:11.265Z
Link: CVE-2023-0681
Updated: 2024-08-02T05:17:50.344Z
Status : Modified
Published: 2023-03-20T20:15:52.470
Modified: 2024-11-21T07:37:37.013
Link: CVE-2023-0681
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD