Medium severity4.3NVD Advisory· Published Mar 30, 2023· Updated Jun 17, 2026
CVE-2023-1699
CVE-2023-1699
Description
Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability. This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.
Affected products
3Patches
Vulnerability mechanics
References
1- docs.rapid7.com/release-notes/nexpose/20230329/nvdRelease Notes
News mentions
0No linked articles in our index yet.