Rapid7 Nexpose SQL Injection



Application Details

Rapid7 Nexpose vulnerability management software monitors exposures in real-time, and adapts to new threats with fresh data.


Vulnerability

Rapid7 Nexpose is vulnerable to SQL injection.


Identification

A remote authenticated attacker could send specially crafted SQL statements to the Security Console, which could allow the attacker to view, add, modify or delete information in the back-end database.


GET /localhost:3780/data/discoveryAsset/config/folderPath?path=[sqli]

Detection

By turning this into a traffic file and matching rule, we are able to detect attempts to influence the vulnerable parameter with SQL injections.


Coverage

Idappcom has created signature 8021561 along with a traffic file.


References

CVE-2020-7383

@ptswarm Tweet


Traffic IQ

If you are concerned that your business may be at risk of this vulnerability or others why not try out our Traffic IQ software which can share your defences and report any issues. Learn more here: https://www.idappcom.co.uk/traffic-iq-professional