CVE-2019-5640: RAPID7 Nexpose
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the inspect element browser feature to remove the login panel and view the details available in the last webpage visited by previous user
Affected products
- RAPID7 Nexpose: before 6.6.114 (fixed in 6.6.114)
Published 2021-11-22. Last modified 2026-06-17.