CVE-2019-5641

LOW

Rapid7 InsightVM < 6.6.160 - Information Exposure via Insufficient Session Expiration

Title source: llm
STIX 2.1

Description

Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Inspect Element browser feature to remove the login panel and view the details available in the last webpage visited by previous user

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://docs.rapid7.com/release-notes/insightvm/20220830/

Scores

CVSS v3 3.3
EPSS 0.0034
EPSS Percentile 26.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-613
Status published
Products (1)
rapid7/insightvm < 6.6.160
Published Sep 21, 2022
Tracked Since Feb 18, 2026