Stored XSS Vulnerability in Nessus by Tenable
CVE-2020-5765

5.4MEDIUM

Key Information:

Vendor

Tenable

Vendor
CVE Published:
15 July 2020

What is CVE-2020-5765?

A Stored XSS vulnerability was identified in Nessus versions 8.10.0 and earlier, stemming from the lack of proper input validation during scan configuration. This flaw allows authenticated remote attackers to potentially inject and execute arbitrary script code within a user's session, posing significant security risks. Tenable mitigated this issue by implementing enhanced input validation in Nessus version 8.11.0.

Affected Version(s)

Tenable Nessus < 8.11.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.