Vulnerability Description
Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the ‘data/console/redirect’ component of the application. This issue was resolved in the February, 2023 release of version 6.6.179.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rapid7 | Insightvm | < 6.6.179 |
Related Weaknesses (CWE)
References
- https://docs.rapid7.com/release-notes/nexpose/20230208/Release Notes
- https://docs.rapid7.com/release-notes/nexpose/20230208/Release Notes
FAQ
What is CVE-2023-0681?
CVE-2023-0681 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ pa...
How severe is CVE-2023-0681?
CVE-2023-0681 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-0681?
Check the references section above for vendor advisories and patch information. Affected products include: Rapid7 Insightvm.