CVE-2023-1699

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
30/03/2023
Last modified:
07/11/2023

Description

Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability.  This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.  

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rapid7:nexpose:*:*:*:*:*:*:*:* 6.6.187 (excluding)


References to Advisories, Solutions, and Tools