CVE-2017-5264

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
14/12/2017
Last modified:
20/04/2025

Description

Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site request forgery (CSRF) attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rapid7:nexpose:*:*:*:*:*:*:*:* 6.4.66 (excluding)