CVE-2022-0757 MEDIUM

CVE-2022-0757: Rapid7 Nexpose SQL Injection

Vendor Rapid7
Product Nexpose
Weakness CWE-89 · SQLi
Published March 17, 2022
Last update September 16, 2024

CVSS base score

5.5/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Rapid7 Nexpose versions 6.6.93 and earlier are susceptible to an SQL Injection vulnerability, whereby valid search operators are not defined. This lack of validation can allow a logged-in, authenticated attacker to manipulate the "ANY" and "OR" operators in the SearchCriteria and inject SQL code. This issue was fixed in Rapid7 Nexpose version 6.6.129.

Key dates

02Disclosure timeline

March 17, 2022 CVE published
September 16, 2024 Record updated