1040918vdb entry
http://www.securitytracker.com/id/1040918 CVE-2018-1147
MEDIUM
Record summary
CVE-2018-1147 has a selected CVSS score of 5.4 (medium).
Description
In Nessus before 7.1.0, a XSS vulnerability exists due to improper input validation. A remote authenticated attacker could create and upload a .nessus file, which may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session. In other scenarios, XSS could also occur by altering variables from the Advanced Settings.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Tenable NessusBrowse Tenable / Tenable Nessus | CVE List | All versions prior to 7.1.0 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-1147 tenable.comConfirmation
https://www.tenable.com/security/tns-2018-05