First published: Thu Mar 30 2023(Updated: )
Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability. This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.
Credit: cve@rapid7.con
Affected Software | Affected Version | How to fix |
---|---|---|
Rapid7 Nexpose | <6.6.187 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-1699.
The severity level of CVE-2023-1699 is critical.
CVE-2023-1699 affects Rapid7 Nexpose versions 6.6.186 and below.
An attacker can exploit CVE-2023-1699 by manipulating URLs to forcefully browse and access administrative pages in Rapid7 Nexpose.
CVE-2023-1699 is fixed in version 6.6.187 of Rapid7 Nexpose.