MEDIUM
Rapid7 Nexpose Reflected XSS
Published Mar 17, 2022
6.1
MEDIUMCVSS 3.1
EPSS 0.43%
Description
Rapid7 Nexpose versions 6.6.129 and earlier suffer from a reflected cross site scripting vulnerability, within the shared scan configuration component of the tool. With this vulnerability an attacker could pass literal values as the test credentials, providing the opportunity for a potential XSS attack. This issue is fixed in Rapid7 Nexpose version 6.6.130.
Affected products
-
Affected
- 6.6.129
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://docs.rapid7.com/release-notes/nexpose/20220309/ x_refsource_CONFIRMRelease NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15821 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://docs.rapid7.com/release-notes/nexpose/20220309/ | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15821 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published Mar 17, 2022
Updated Sep 16, 2024
Reserved Feb 24, 2022
Link CVE-2022-0758
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data