Medium severity5.5NVD Advisory· Published Mar 17, 2022· Updated Jun 17, 2026
CVE-2022-0757
CVE-2022-0757
Description
Rapid7 Nexpose versions 6.6.93 and earlier are susceptible to an SQL Injection vulnerability, whereby valid search operators are not defined. This lack of validation can allow a logged-in, authenticated attacker to manipulate the "ANY" and "OR" operators in the SearchCriteria and inject SQL code. This issue was fixed in Rapid7 Nexpose version 6.6.129.
Affected products
3Patches
Vulnerability mechanics
References
1- docs.rapid7.com/release-notes/nexpose/20220302/nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.