PT-2020-4730 · Rapid7 · Nexpose

Mikhail Klyuchnikov

·

Published

2020-10-14

·

Updated

2021-07-16

·

CVE-2020-7383

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions: Rapid7 Nexpose versions prior to 6.6.49
Description: The issue is related to insufficient protection of the SQL query structure, which may allow a remote attacker to elevate their privileges. It is a SQL Injection issue that may have allowed an authenticated user with a low permission level to access resources and make changes they should not have been able to access.
Recommendations: For versions prior to 6.6.49, update to version 6.6.49 or later to resolve the issue. As a temporary workaround, consider restricting access to the SQL query structure to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05282
CVE-2020-7383

Affected Products

Nexpose