Vulnerabilities > Rapid7 > Insightvm > 6.6.13

DATE CVE VULNERABILITY TITLE RISK
2023-03-20 CVE-2023-0681 Open Redirect vulnerability in Rapid7 Insightvm
Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the ‘data/console/redirect’ component of the application.
network
low complexity
rapid7 CWE-601
6.1
2022-12-08 CVE-2022-4261 Download of Code Without Integrity Check vulnerability in Rapid7 Insightvm
Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents.
network
low complexity
rapid7 CWE-494
6.5