Rapid7 Nexpose CVE-2017-5264 Cross Site Request Forgery Vulnerability



Nexpose is prone to a cross-site request-forgery vulnerability.

Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Versions prior to Nexpose 6.4.66 are vulnerable.

Information

Bugtraq ID: 102208
Class: Unknown
CVE: CVE-2017-5264

Remote: Yes
Local: No
Published: Dec 13 2017 12:00AM
Updated: Dec 13 2017 12:00AM
Credit: The vendor reported this issue.
Vulnerable: Rapid7 Nexpose 6.4.65
Rapid7 Nexpose 6.4.13
Rapid7 Nexpose 6.4.12
Rapid7 Nexpose 5.8.6
Rapid7 Nexpose 5.8
Rapid7 Nexpose 5.7.5
Rapid7 Nexpose 5.5.4
Rapid7 Nexpose 5.5.3
Rapid7 Nexpose 5.4.8
Rapid7 Nexpose 5.4.7
Rapid7 Nexpose 5.4.6
Rapid7 Nexpose 5.5.8
Rapid7 Nexpose 5.5.7
Rapid7 Nexpose 5.5.6
Rapid7 Nexpose 5.5.5
Rapid7 Nexpose 5.5.1
Rapid7 Nexpose 5.4.9
Rapid7 Nexpose 5.4.5
Rapid7 Nexpose 5.4.4
Rapid7 Nexpose 5.4.3
Rapid7 Nexpose 5.4.2
Rapid7 Nexpose 5.4.12
Rapid7 Nexpose 5.4.11
Rapid7 Nexpose 5.4.10
Rapid7 Nexpose 5.4.1
Rapid7 Nexpose 5.4


Not Vulnerable: Rapid7 Nexpose 6.4.66


Exploit


An attacker can exploit these issues by enticing an unsuspecting user to follow a malicious URI.


References:

Related Posts