6.1
CVSSv3

CVE-2018-11473

Published: 25/05/2018 Updated: 26/06/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Nessus versions 7.0.3 and previous versions have been found vulnerable to two separate issues. The first vulnerability (XSS) exists due to improper input validation. An authenticated attacker could create and upload a .nessus file, that may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session. In other scenarios, XSS could occur by altering system variables from the Advanced Settings. CVE-2018-1147 - CVSSv2 (AV:A/AC:H/Au:M/C:P/I:C/A:P/E:POC/RL:OF/RC:C/CDP:L/TD:L/CR:L/IR:L/AR:L) The second vulnerability (Session Fixation) exists due to insufficient session management. An authenticated attacker could maintain system access after a password change due to session fixation. CVE-2018-1148 - CVSSv2 (AV:N/AC:M/Au:S/C:N/I:P/A:N/E:POC/RL:OF/RC:C/CDP:L/TD:M/CR:ND/IR:ND/AR:ND)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

monstra monstra 3.0.4

Vendor Advisories

Nessus versions 703 and earlier have been found vulnerable to two separate issues The first vulnerability (XSS) exists due to improper input validation An authenticated attacker could create and upload a nessus file, that may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session In othe ...