CWE
79
Advisory Published
Updated

CVE-2020-7355: Rapid7 Metasploit Pro Stored XSS in 'notes' field

First published: Thu Jun 25 2020(Updated: )

Cross-site Scripting (XSS) vulnerability in the 'notes' field of a discovered scan asset in Rapid7 Metasploit Pro allows an attacker with a specially-crafted network service of a scan target store an XSS sequence in the Metasploit Pro console, which will trigger when the operator views the record of that scanned host in the Metasploit Pro interface. This issue affects Rapid7 Metasploit Pro version 4.17.1-20200427 and prior versions, and is fixed in Metasploit Pro version 4.17.1-20200514. See also CVE-2020-7354, which describes a similar issue, but involving the generated 'host' field of a discovered scan asset.

Credit: cve@rapid7.con

Affected SoftwareAffected VersionHow to fix
Rapid7 Metasploit<4.17.1
Rapid7 Metasploit=4.17.1
Rapid7 Metasploit=4.17.1-20170221
Rapid7 Metasploit=4.17.1-20170323
Rapid7 Metasploit=4.17.1-20170405
Rapid7 Metasploit=4.17.1-20170419
Rapid7 Metasploit=4.17.1-20170510
Rapid7 Metasploit=4.17.1-20170518
Rapid7 Metasploit=4.17.1-20170530
Rapid7 Metasploit=4.17.1-20170613
Rapid7 Metasploit=4.17.1-20170627
Rapid7 Metasploit=4.17.1-20170718
Rapid7 Metasploit=4.17.1-20170731
Rapid7 Metasploit=4.17.1-20170816
Rapid7 Metasploit=4.17.1-20170828
Rapid7 Metasploit=4.17.1-20170914
Rapid7 Metasploit=4.17.1-20170926
Rapid7 Metasploit=4.17.1-20171009
Rapid7 Metasploit=4.17.1-20171030
Rapid7 Metasploit=4.17.1-20171115
Rapid7 Metasploit=4.17.1-20171129
Rapid7 Metasploit=4.17.1-20171206
Rapid7 Metasploit=4.17.1-20171220
Rapid7 Metasploit=4.17.1-20180108
Rapid7 Metasploit=4.17.1-20180124
Rapid7 Metasploit=4.17.1-20180206
Rapid7 Metasploit=4.17.1-20180301
Rapid7 Metasploit=4.17.1-20180312
Rapid7 Metasploit=4.17.1-20180327
Rapid7 Metasploit=4.17.1-20180410
Rapid7 Metasploit=4.17.1-20180501
Rapid7 Metasploit=4.17.1-20180511
Rapid7 Metasploit=4.17.1-20180526
Rapid7 Metasploit=4.17.1-20180618
Rapid7 Metasploit=4.17.1-20180704
Rapid7 Metasploit=4.17.1-20180716
Rapid7 Metasploit=4.17.1-20180727
Rapid7 Metasploit=4.17.1-20180813
Rapid7 Metasploit=4.17.1-20180827
Rapid7 Metasploit=4.17.1-20180907
Rapid7 Metasploit=4.17.1-20180924
Rapid7 Metasploit=4.17.1-20181009
Rapid7 Metasploit=4.17.1-20181022
Rapid7 Metasploit=4.17.1-20181105
Rapid7 Metasploit=4.17.1-20181130
Rapid7 Metasploit=4.17.1-20181215
Rapid7 Metasploit=4.17.1-20190108
Rapid7 Metasploit=4.17.1-20190118
Rapid7 Metasploit=4.17.1-20190201
Rapid7 Metasploit=4.17.1-20190219
Rapid7 Metasploit=4.17.1-20190303
Rapid7 Metasploit=4.17.1-20190319
Rapid7 Metasploit=4.17.1-20190331
Rapid7 Metasploit=4.17.1-20190416
Rapid7 Metasploit=4.17.1-20190426
Rapid7 Metasploit=4.17.1-20190513
Rapid7 Metasploit=4.17.1-20190603
Rapid7 Metasploit=4.17.1-20190607
Rapid7 Metasploit=4.17.1-20190626
Rapid7 Metasploit=4.17.1-20190722
Rapid7 Metasploit=4.17.1-20190805
Rapid7 Metasploit=4.17.1-20190819
Rapid7 Metasploit=4.17.1-20190910
Rapid7 Metasploit=4.17.1-20190930
Rapid7 Metasploit=4.17.1-20191014
Rapid7 Metasploit=4.17.1-20191030
Rapid7 Metasploit=4.17.1-20191108
Rapid7 Metasploit=4.17.1-20191209
Rapid7 Metasploit=4.17.1-20200113
Rapid7 Metasploit=4.17.1-20200122
Rapid7 Metasploit=4.17.1-20200131
Rapid7 Metasploit=4.17.1-20200218
Rapid7 Metasploit=4.17.1-20200302
Rapid7 Metasploit=4.17.1-20200318
Rapid7 Metasploit=4.17.1-20200330
Rapid7 Metasploit=4.17.1-20200413

Remedy

Update to Metasploit Pro version 4.17.1-20200514 to fix this issue.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203