// For flags

CVE-2020-7354

Rapid7 Metasploit Pro Stored XSS in 'host' field

Severity Score

5.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cross-site Scripting (XSS) vulnerability in the 'host' field of a discovered scan asset in Rapid7 Metasploit Pro allows an attacker with a specially-crafted network service of a scan target to store an XSS sequence in the Metasploit Pro console, which will trigger when the operator views the record of that scanned host in the Metasploit Pro interface. This issue affects Rapid7 Metasploit Pro version 4.17.1-20200427 and prior versions, and is fixed in Metasploit Pro version 4.17.1-20200514. See also CVE-2020-7355, which describes a similar issue, but involving the generated 'notes' field of a discovered scan asset.

Una vulnerabilidad de tipo Cross-site Scripting (XSS) en el campo "host" de un activo de escaneo detectado en Rapid7 Metasploit Pro, permite a un atacante con un servicio de red especialmente diseñado de un objetivo de escaneo almacenar una secuencia de tipo XSS en la consola Metasploit Pro, que se activará cuando el operador visualiza el registro de ese host escaneado en la interfaz Metasploit Pro. Este problema afecta a Rapid7 Metasploit Pro versión 4.17.1-20200427 y versiones anteriores, y es corregido en Metasploit Pro versión 4.17.1-20200514. Consulte también CVE-2020-7355, que describe un problema similar, pero involucrando el campo "notes" generado de un activo de escaneo detectado

*Credits: Andrea Valenza at the University of Genoa discovered and reported this issue to Rapid7
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-01-21 CVE Reserved
  • 2020-06-25 CVE Published
  • 2023-03-11 EPSS Updated
  • 2024-09-17 CVE Updated
  • 2024-09-17 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
< 4.17.1
Search vendor "Rapid7" for product "Metasploit" and version " < 4.17.1"
pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20170221, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20170323, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20170405, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20170419, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20170510, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20170518, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20170530, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20170613, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20170627, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20170718, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20170731, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20170816, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20170828, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20170914, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20170926, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20171009, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20171030, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20171115, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20171129, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20171206, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20171220, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180108, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180124, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180206, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180301, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180312, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180327, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180410, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180501, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180511, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180526, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180618, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180704, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180716, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180727, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180813, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180827, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180907, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20180924, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20181009, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20181022, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20181105, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20181130, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20181215, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190108, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190118, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190201, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190219, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190303, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190319, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190331, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190416, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190426, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190513, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190603, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190607, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190626, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190722, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190805, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190819, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190910, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20190930, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20191014, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20191030, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20191108, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20191209, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20200113, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20200122, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20200131, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20200218, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20200302, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20200318, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20200330, pro
Affected
Rapid7
Search vendor "Rapid7"
Metasploit
Search vendor "Rapid7" for product "Metasploit"
4.17.1
Search vendor "Rapid7" for product "Metasploit" and version "4.17.1"
20200413, pro
Affected