High severity8.8NVD Advisory· Published Dec 14, 2017· Updated May 13, 2026
CVE-2017-5264
CVE-2017-5264
Description
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site request forgery (CSRF) attack.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/102208nvdThird Party AdvisoryVDB Entry
- help.rapid7.com/nexpose/en-us/release-notes/archive/2017/12/nvdRelease Notes
- www.exploit-db.com/exploits/43911/nvd
News mentions
0No linked articles in our index yet.