Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hhqx-5j72-qf6h

Опубликовано: 30 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability. This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.

Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability. This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.

EPSS

Процентиль: 26%
0.00089
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-425

Связанные уязвимости

CVSS3: 4.3
nvd
почти 3 года назад

Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability.  This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.  

EPSS

Процентиль: 26%
0.00089
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-425