CVE-2019-5630
HIGH 8.8EPSS 0.9%
A Cross-Site Request Forgery (CSRF) vulnerability was found in Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68. This issue allows attackers to exploit CSRF vulnerabilities on API endpoints using Flash to circumvent a cross-domain pre-flight OPTIONS request.
- CVSS v3.0
- 8.8 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.0
- 5.9 MEDIUM
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 0.89% chance of exploitation in the next 30 days, 57th percentile
- Published
- 2019-07-03
- Updated
- 2024-08-04
Proof-of-concept exploits (1)
- rbeede/CVE-2019-56300★ · 2020-01-07