← Back

CVE-2020-7354

nvd nist
Published: Jun 25, 2020Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: NVD

Description

Cross-site Scripting (XSS) vulnerability in the 'host' field of a discovered scan asset in Rapid7 Metasploit Pro allows an attacker with a specially-crafted network service of a scan target to store an XSS sequence in the Metasploit Pro console, which will trigger when the operator views the record of that scanned host in the Metasploit Pro interface. This issue affects Rapid7 Metasploit Pro version 4.17.1-20200427 and prior versions, and is fixed in Metasploit Pro version 4.17.1-20200514. See also CVE-2020-7355, which describes a similar issue, but involving the generated 'notes' field of a discovered scan asset.

Affected (76)

Products: Rapid7: Metasploit
1 product
Metasploit
Configuration A
76 vulnerable
Vulnerable SoftwareAffected Versions
Rapid7
Before 4.17.1
Version 4.17.1
Version 4.17.1 20170221
Version 4.17.1 20170323
Version 4.17.1 20170405
Version 4.17.1 20170419
Version 4.17.1 20170510
Version 4.17.1 20170518
Version 4.17.1 20170530
Version 4.17.1 20170613
Version 4.17.1 20170627
Version 4.17.1 20170718
Version 4.17.1 20170731
Version 4.17.1 20170816
Version 4.17.1 20170828
Version 4.17.1 20170914
Version 4.17.1 20170926
Version 4.17.1 20171009
Version 4.17.1 20171030
Version 4.17.1 20171115
Version 4.17.1 20171129
Version 4.17.1 20171206
Version 4.17.1 20171220
Version 4.17.1 20180108
Version 4.17.1 20180124
Version 4.17.1 20180206
Version 4.17.1 20180301
Version 4.17.1 20180312
Version 4.17.1 20180327
Version 4.17.1 20180410
Version 4.17.1 20180501
Version 4.17.1 20180511
Version 4.17.1 20180526
Version 4.17.1 20180618
Version 4.17.1 20180704
Version 4.17.1 20180716
Version 4.17.1 20180727
Version 4.17.1 20180813
Version 4.17.1 20180827
Version 4.17.1 20180907
Version 4.17.1 20180924
Version 4.17.1 20181009
Version 4.17.1 20181022
Version 4.17.1 20181105
Version 4.17.1 20181130
Version 4.17.1 20181215
Version 4.17.1 20190108
Version 4.17.1 20190118
Version 4.17.1 20190201
Version 4.17.1 20190219
Version 4.17.1 20190303
Version 4.17.1 20190319
Version 4.17.1 20190331
Version 4.17.1 20190416
Version 4.17.1 20190426
Version 4.17.1 20190513
Version 4.17.1 20190603
Version 4.17.1 20190607
Version 4.17.1 20190626
Version 4.17.1 20190722
Version 4.17.1 20190805
Version 4.17.1 20190819
Version 4.17.1 20190910
Version 4.17.1 20190930
Version 4.17.1 20191014
Version 4.17.1 20191030
Version 4.17.1 20191108
Version 4.17.1 20191209
Version 4.17.1 20200113
Version 4.17.1 20200122
Version 4.17.1 20200131
Version 4.17.1 20200218
Version 4.17.1 20200302
Version 4.17.1 20200318
Version 4.17.1 20200330
Version 4.17.1 20200413

References (4)

Source: cve@rapid7.com
ExploitThird Party Advisory
Source: cve@rapid7.com
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.