CVE-2024-1471

MEDIUM

Tenable Security Center < 6.3.0 - Authenticated HTML Injection via Repository Parameters

Title source: llm
STIX 2.1

Description

An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection attacks.

References (1)

Core 1
Core References

Scores

CVSS v3 5.9
EPSS 0.0016
EPSS Percentile 35.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-79
Status published
Products (1)
tenable/security_center < 6.3.0
Published Feb 14, 2024
Tracked Since Feb 18, 2026