5.4
CVSSv3

CVE-2018-1147

Published: 18/05/2018 Updated: 19/06/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

In Nessus prior to 7.1.0, a XSS vulnerability exists due to improper input validation. A remote authenticated attacker could create and upload a .nessus file, which may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session. In other scenarios, XSS could also occur by altering variables from the Advanced Settings.

Vulnerable Product Search on Vulmon Subscribe to Product

tenable nessus

Vendor Advisories

Nessus versions 703 and earlier have been found vulnerable to two separate issues The first vulnerability (XSS) exists due to improper input validation An authenticated attacker could create and upload a nessus file, that may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session In othe ...