RULE(RULE ID:333859)

Rule General Information
Release Date: 2021-07-27
Rule Name: Rapid7 Nexpose SQL Injection Vulnerability (CVE-2020-7383)
Severity:
CVE ID:
Rule Protection Details
Description: A SQL Injection issue in Rapid7 Nexpose version prior to 6.6.49 that may have allowed an authenticated user with a low permission level to access resources & make changes they should not have been able to access.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference: https://help.rapid7.com/insightvm/en-us/release-notes/index.html?pid=6.6.49
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://help.rapid7.com/insightvm/en-us/release-notes/index.html?pid=6.6.49