peter bassill · operator
$ cve CVE-2017-5264 JSON

CVE-2017-5264 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 2.7% (pctl 86)

Patch early

A public exploit exists.

Description

Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site request forgery (CSRF) attack.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS2.75% — more likely to be exploited than 86% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2017-12-14
Last modified2026-06-17

Affected (1)

VendorProduct
rapid7nexpose

Public exploits

SourceTitleDate
exploit-dbNexpose < 6.4.66 - Cross-Site Request Forgery2018-01-28

References

→ the Explorer  ·  watch your stack  ·  NVD