CVE-2017-15084: RAPID7 Metasploit

Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.

The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.

Affected products

  • RAPID7 Metasploit: up to and including 4.14.1

Published 2017-10-06. Last modified 2026-06-17.