CVE-2017-2122

MEDIUM

Nessus <6.9.2 - XSS

Title source: llm

Description

Cross-site scripting vulnerability in Nessus versions 6.8.0, 6.8.1, 6.9.0, 6.9.1 and 6.9.2 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

Scores

CVSS v3 5.4
EPSS 0.0037
EPSS Percentile 58.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (10)
tenable/nessus
tenable/nessus
tenable/nessus
tenable/nessus
tenable/nessus
Tenable Network Security, Inc./Nessus < 6.8.0
Tenable Network Security, Inc./Nessus < 6.8.1
Tenable Network Security, Inc./Nessus < 6.9.0
Tenable Network Security, Inc./Nessus < 6.9.1
Tenable Network Security, Inc./Nessus < 6.9.2
Published May 12, 2017
Tracked Since Feb 18, 2026