CVE-2019-5640
Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the inspect element browser feature to remove the login panel and view the details available in the last webpage visited by previous user
Published
2021-11-22T17:15:08.357
Last Modified
2024-11-21T04:45:17.270
Status
Modified
Source
[email protected]
Severity
CVSSv3.1: 3.3 (LOW)
CVSSv2 Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
- Access Vector: NETWORK
- Access Complexity: LOW
- Authentication: NONE
- Confidentiality Impact: PARTIAL
- Integrity Impact: NONE
- Availability Impact: NONE
Exploitability Score
10.0
Impact Score
2.9
Weaknesses
-
Type: Secondary
CWE-200
-
Type: Primary
CWE-200
Affected Vendors & Products
Type |
Vendor |
Product |
Version/Range |
Vulnerable? |
Application |
rapid7
|
nexpose
|
< 6.6.114 |
Yes
|
References