Cross-Site Scripting Vulnerability in Nessus by Tenable
CVE-2014-7280
Currently unrated
What is CVE-2014-7280?
A Cross-Site Scripting vulnerability exists in the Web User Interface of Tenable Nessus 5.x versions prior to 2.3.4 Build #85. This flaw allows remote web servers to inject arbitrary web scripts or HTML content through crafted server headers. Successful exploitation could lead to various security risks, including the execution of malicious scripts in the user's browser, potentially compromising user credentials and session information. It is crucial for users of affected Nessus versions to apply available updates promptly to mitigate this vulnerability.