vendor:
Nexpose
by:
Shwetabh Vishnoi
8.8
CVSS
HIGH
Cross Site Request Forgery
352
CWE
Product Name: Nexpose
Affected Version From: Rapid7 Nexpose 6.4.65
Affected Version To: Rapid7 Nexpose 5.4
Patch Exists: YES
Related CWE: CVE-2017-5264
CPE: a:rapid7:nexpose
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows,Linux,Mac
2017
Cross Site Request Forgery at Nexpose Automated Actions
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site request forgery (CSRF) attack.
Mitigation:
Update to 6.4.66