Vulnerabilities > Rapid7 > Metasploit

DATE CVE VULNERABILITY TITLE RISK
2019-04-30 CVE-2019-5624 Path Traversal vulnerability in Rapid7 Metasploit
Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in the Zip import function of Metasploit.
local
low complexity
rapid7 CWE-22
7.3
2017-10-06 CVE-2017-15084 Cross-Site Request Forgery (CSRF) vulnerability in Rapid7 Metasploit
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
network
rapid7 CWE-352
4.3
2017-06-15 CVE-2017-5244 Cross-Site Request Forgery (CSRF) vulnerability in Rapid7 Metasploit 4.13.0/4.13.1/4.13.19
Routes used to stop running Metasploit tasks (either particular ones or all tasks) allowed GET requests.
network
rapid7 CWE-352
3.5
2017-03-02 CVE-2017-5235 Untrusted Search Path vulnerability in Rapid7 Metasploit 4.13.0
Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
network
rapid7 CWE-426
6.8
2017-03-02 CVE-2017-5231 Path Traversal vulnerability in Rapid7 Metasploit 4.13.0/4.13.1/4.13.19
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function.
network
high complexity
rapid7 CWE-22
5.1
2017-03-02 CVE-2017-5229 Path Traversal vulnerability in Rapid7 Metasploit 4.13.0/4.13.1/4.13.19
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.parse_dump() function.
network
high complexity
rapid7 CWE-22
5.1
2017-03-02 CVE-2017-5228 Path Traversal vulnerability in Rapid7 Metasploit 4.13.0/4.13.1/4.13.19
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function.
network
high complexity
rapid7 CWE-22
5.1