Nessus versions 7.0.3 and previous versions have been found vulnerable to two separate issues. The first vulnerability (XSS) exists due to improper input validation. An authenticated attacker could create and upload a .nessus file, that may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session. In other scenarios, XSS could occur by altering system variables from the Advanced Settings. CVE-2018-1147 - CVSSv2 (AV:A/AC:H/Au:M/C:P/I:C/A:P/E:POC/RL:OF/RC:C/CDP:L/TD:L/CR:L/IR:L/AR:L) The second vulnerability (Session Fixation) exists due to insufficient session management. An authenticated attacker could maintain system access after a password change due to session fixation. CVE-2018-1148 - CVSSv2 (AV:N/AC:M/Au:S/C:N/I:P/A:N/E:POC/RL:OF/RC:C/CDP:L/TD:M/CR:ND/IR:ND/AR:ND)
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
monstra monstra 3.0.4 |