CVE-2018-1142

MEDIUM

Tenable Appliance <= 4.6.1 - Authenticated Cross-Site Scripting via Offline Plugin URL Parameters

Title source: llm
STIX 2.1

Description

Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability. Utilizing a specially crafted request, an authenticated attacker could potentially execute arbitrary JavaScript code by manipulating certain URL parameters related to offline plugins.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.tenable.com/security/tns-2018-02

Scores

CVSS v3 5.4
EPSS 0.0029
EPSS Percentile 52.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
tenable/appliance < 4.6.1
Published Mar 28, 2018
Tracked Since Feb 18, 2026