CVE-2021-3535
Last modified
CVE-2021-3535 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Rapid7 Nexpose is vulnerable to a non-persistent cross-site scripting vulnerability affecting the Security Console's Filtered Asset Search feature. A specific search criterion and operator combination in Filtered Asset Search could have allowed a user to pass code through the provided search field. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
Rapid7 Nexpose is vulnerable to a non-persistent cross-site scripting vulnerability affecting the Security Console's Filtered Asset Search feature. A specific search criterion and operator combination in Filtered Asset Search could have allowed a user to pass code through the provided search field. This issue affects version 6.6.80 and prior, and is fixed in 6.6.81. If your Security Console currently falls on or within this affected version range, ensure that you update your Security Console to the latest version.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rapid7 | Nexpose | < 6.6.81 |
References
- https://docs.rapid7.com/release-notes/nexpose/20210505/Release Notes, Vendor Advisory
- https://docs.rapid7.com/release-notes/nexpose/20210505/Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3535?
How severe is CVE-2021-3535?
How do I fix CVE-2021-3535?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-35337Sourcecodester Phone Shop Sales Managements System 1.0 is vu…4.3
- CVE-2021-3534Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-35342The useradm service 1.14.0 (in Northern.tech Mender Enterpri…7.5
- CVE-2021-35343Cross-Site Request Forgery (CSRF) vulnerability in the /op/o…4.3
- CVE-2021-35344tsMuxer v2.6.16 was discovered to contain a heap-based buffe…9.8
- CVE-2021-35346tsMuxer v2.6.16 was discovered to contain a heap-based buffe…9.8
- CVE-2021-35358A stored cross site scripting (XSS) vulnerability in dotAdmi…4.8
- CVE-2021-3536A flaw was found in Wildfly in versions before 23.0.2.Final …4.8
- CVE-2021-35360A reflected cross site scripting (XSS) vulnerability in dotA…4.8
- CVE-2021-35361A reflected cross site scripting (XSS) vulnerability in dotA…4.8
- CVE-2021-35368OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x be…9.8
- CVE-2021-35369Arbitrary File Read vulnerability found in Peacexie ImCat v.…6.5
Are you affected by CVE-2021-3535?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
