Description
Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability. This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-23927 | Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability. This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187. |
References
| Link | Providers |
|---|---|
| https://docs.rapid7.com/release-notes/nexpose/20230329/ |
|
History
Tue, 11 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2025-02-11T20:12:14.684Z
Reserved: 2023-03-29T14:17:15.354Z
Link: CVE-2023-1699
Updated: 2024-08-02T05:57:25.055Z
Status : Modified
Published: 2023-03-30T10:15:07.137
Modified: 2024-11-21T07:39:43.460
Link: CVE-2023-1699
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD