CVE-2018-1142

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
28/03/2018
Last modified:
19/04/2018

Description

Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability. Utilizing a specially crafted request, an authenticated attacker could potentially execute arbitrary JavaScript code by manipulating certain URL parameters related to offline plugins.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tenable:appliance:*:*:*:*:*:*:*:* 4.6.1 (including)


References to Advisories, Solutions, and Tools