ZeroHour

CVE-2023-1699

CVSS 3.1
9.8 critical
EPSS
<1%p38
Published
()
Modified
Description

Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability. This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.

Vendors
rapid7
Products
nexpose
Weakness
CWE-425
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.