Cross-Site Scripting Vulnerability in Nessus by Tenable
CVE-2018-1147

5.4MEDIUM

Key Information:

Vendor

Tenable

Vendor
CVE Published:
18 May 2018

What is CVE-2018-1147?

Nessus versions prior to 7.1.0 are vulnerable to a Cross-Site Scripting (XSS) attack due to improper input validation. This flaw allows a remote, authenticated attacker to create and upload a malicious .nessus file. If an administrator views this file, arbitrary script code could be executed in the context of the administrator's browser session, potentially compromising sensitive information. Additionally, XSS could be triggered by manipulating variables in the Advanced Settings. Organizations using affected versions of Nessus should apply the latest updates to mitigate this vulnerability.

Affected Version(s)

Tenable Nessus All versions prior to 7.1.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.