header-logo
Suggest Exploit
vendor:
Nexpose Security Console
by:
Robert Gilbert, HALOCK Security Labs
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Nexpose Security Console
Affected Version From: < 5.5.3
Affected Version To: 5.5.1
Patch Exists: YES
Related CWE: CVE-2012-6493
CPE: a:rapid7:nexpose_security_console
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2012

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Nexpose Security Console 5.5.3 and below

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Nexpose Security Console 5.5.3 and below allow remote attackers to submit actions on a legitimate user’s behalf. By not properly checking each URL, an attacker can execute requests on behalf of a legitimate user. If an authenticated user is tricked into visiting a specially crafted page, it may be possible to perform user-initiated actions on the web application using the victim’s established session. Successful exploitation of this vulnerability resulted in deleting scan data and sites during the proof-of-concept.

Mitigation:

Vendor Update: Remediated in 5.5.4.
Source

Exploit-DB raw data: