CVE-2023-1699: Rapid7 Nexpose Forced Browsing
Published Mar 30, 2023
·Updated
Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability. This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.
Affected Software
1 affected component
Rapid7 Nexpose<6.6.187
Event History
Mar 30, 2023
CVE Published
via MITRE·09:26 AM
Data Sourced
via MITRE·09:26 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-1699.
2
What is the severity level of CVE-2023-1699?
The severity level of CVE-2023-1699 is critical.
3
How does CVE-2023-1699 affect Rapid7 Nexpose?
CVE-2023-1699 affects Rapid7 Nexpose versions 6.6.186 and below.
4
How can an attacker exploit CVE-2023-1699?
An attacker can exploit CVE-2023-1699 by manipulating URLs to forcefully browse and access administrative pages in Rapid7 Nexpose.
5
How can I fix CVE-2023-1699?
CVE-2023-1699 is fixed in version 6.6.187 of Rapid7 Nexpose.