CVE-2018-1147Cross-site Scripting in Nessus

Severity
5.4MEDIUMNVD
EPSS
0.4%
top 41.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 18
Latest updateMay 14

Description

In Nessus before 7.1.0, a XSS vulnerability exists due to improper input validation. A remote authenticated attacker could create and upload a .nessus file, which may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session. In other scenarios, XSS could also occur by altering variables from the Advanced Settings.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

NVDtenable/nessus< 7.1.0
CVEListV5tenable/tenable_nessusAll versions prior to 7.1.0

🔴Vulnerability Details

2
GHSA
GHSA-wp62-w6xh-5jjc: In Nessus before 72022-05-14
CVEList
CVE-2018-1147: In Nessus before 72018-05-18
CVE-2018-1147 — Cross-site Scripting in Tenable Nessus | cvebase