VYPR
Low severity3.3NVD Advisory· Published Nov 22, 2021· Updated Jun 17, 2026

CVE-2019-5640

CVE-2019-5640

Description

Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the inspect element browser feature to remove the login panel and view the details available in the last webpage visited by previous user

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Rapid7/Nexpose3 versions
    cpe:2.3:a:rapid7:nexpose:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:rapid7:nexpose:*:*:*:*:*:*:*:*range: <6.6.114
    • (no CPE)range: <6.6.114
    • (no CPE)range: 1.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.