Medium severity5.4NVD Advisory· Published Dec 20, 2016· Updated May 6, 2026
CVE-2016-9757
CVE-2016-9757
Description
In the Create Tags page of the Rapid7 Nexpose version 6.4.12 user interface, any authenticated user who has the capability to create tags can inject cross-site scripting (XSS) elements in the tag name field. Once this tag is viewed in the Tag Detail page of the Rapid7 Nexpose 6.4.12 UI by another authenticated user, the script is run in that user's browser context.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/94996nvdThird Party AdvisoryVDB Entry
- help.rapid7.com/nexpose/en-us/release-notes/nvdVendor Advisory
News mentions
0No linked articles in our index yet.