CVE-2023-1699

Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability.  This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.  
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:rapid7:nexpose:*:*:*:*:*:*:*:*

History

07 Nov 2023, 04:04

Type Values Removed Values Added
Summary Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability. This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187. Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability.  This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.  

Information

Published : 2023-03-30 10:15

Updated : 2024-02-28 20:13


NVD link : CVE-2023-1699

Mitre link : CVE-2023-1699

CVE.ORG link : CVE-2023-1699


JSON object : View

Products Affected

rapid7

  • nexpose
CWE
CWE-425

Direct Request ('Forced Browsing')