CVE-2018-1147

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
18/05/2018
Last modified:
19/06/2018

Description

In Nessus before 7.1.0, a XSS vulnerability exists due to improper input validation. A remote authenticated attacker could create and upload a .nessus file, which may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session. In other scenarios, XSS could also occur by altering variables from the Advanced Settings.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:* 7.1.0 (excluding)