CVE-2019-3962

LOW

Tenable Nessus < 8.5.0 - Authenticated Content Injection via Feed Status

Title source: llm
STIX 2.1

Description

Content Injection vulnerability in Tenable Nessus prior to 8.5.0 may allow an authenticated, local attacker to exploit this vulnerability by convincing another targeted Nessus user to view a malicious URL and use Nessus to send fraudulent messages. Successful exploitation could allow the authenticated adversary to inject arbitrary text into the feed status, which will remain saved post session expiration.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://www.tenable.com/security/tns-2019-04
Third Party Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/109025

Scores

CVSS v3 3.3
EPSS 0.0023
EPSS Percentile 45.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
tenable/nessus < 8.5.0
Published Jul 01, 2019
Tracked Since Feb 18, 2026