CVE-2019-5641

LOW

Rapid7 InsightVM < 6.6.160 - Information Exposure via Insufficient Session Expiration

Title source: llm
STIX 2.1

Description

Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Inspect Element browser feature to remove the login panel and view the details available in the last webpage visited by previous user

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://docs.rapid7.com/release-notes/insightvm/20220830/

Scores

CVSS v3 3.3
EPSS 0.0032
EPSS Percentile 23.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-613 CWE-200
Status published
Products (1)
rapid7/insightvm < 6.6.160
Published Sep 21, 2022
Tracked Since Feb 18, 2026