6.5
CVSSv3

CVE-2018-1148

Published: 18/05/2018 Updated: 20/06/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

In Nessus prior to 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could maintain system access due to session fixation after a user password change.

Vulnerable Product Search on Vulmon Subscribe to Product

tenable nessus

Vendor Advisories

Nessus versions 703 and earlier have been found vulnerable to two separate issues The first vulnerability (XSS) exists due to improper input validation An authenticated attacker could create and upload a nessus file, that may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session In othe ...