First published: Thu May 06 2021(Updated: )
Rapid7 Nexpose is vulnerable to a non-persistent cross-site scripting vulnerability affecting the Security Console's Filtered Asset Search feature. A specific search criterion and operator combination in Filtered Asset Search could have allowed a user to pass code through the provided search field. This issue affects version 6.6.80 and prior, and is fixed in 6.6.81. If your Security Console currently falls on or within this affected version range, ensure that you update your Security Console to the latest version.
Credit: cve@rapid7.con
Affected Software | Affected Version | How to fix |
---|---|---|
Rapid7 Nexpose | <6.6.81 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3535 is a non-persistent cross-site scripting vulnerability in Rapid7 Nexpose's Filtered Asset Search feature.
CVE-2021-3535 has a severity rating of 6.1, which is considered medium.
CVE-2021-3535 affects Rapid7 Nexpose versions up to 6.6.81 by allowing a user to pass code through the search field in the Filtered Asset Search feature.
To fix CVE-2021-3535, you should update Rapid7 Nexpose to a version beyond 6.6.81.
You can find more information about CVE-2021-3535 in the Rapid7 Nexpose release notes at [https://docs.rapid7.com/release-notes/nexpose/20210505/](https://docs.rapid7.com/release-notes/nexpose/20210505/).