Rapid7 Metasploit Pro Stored XSS
CVE-2023-0599

6.1MEDIUM

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
1 February 2023

What is CVE-2023-0599?

Rapid7 Metasploit Pro versions 4.21.2 and lower suffer from a stored cross site scripting vulnerability, due to a lack of JavaScript request string sanitization.  Using this vulnerability, an authenticated attacker can execute arbitrary HTML and script code in the target browser against another Metasploit Pro user using a specially crafted request. Note that in most deployments, all Metasploit Pro users tend to enjoy privileges equivalent to local administrator.

Affected Version(s)

Metasploit Pro 0 <= 4.21.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Caruso
.
CVE-2023-0599 : Rapid7 Metasploit Pro Stored XSS