A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary scripts.
References
Link | Resource |
---|---|
https://www.tenable.com/security/tns-2024-01 | Vendor Advisory |
https://www.tenable.com/security/tns-2024-01 | Vendor Advisory |
Configurations
History
21 Nov 2024, 08:47
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.tenable.com/security/tns-2024-01 - Vendor Advisory |
14 Feb 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.tenable.com/security/tns-2024-01 - Vendor Advisory | |
Summary |
|
|
First Time |
Tenable nessus
Tenable |
|
CPE | cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:* | |
CWE | CWE-79 |
07 Feb 2024, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-07 00:15
Updated : 2024-11-21 08:47
NVD link : CVE-2024-0955
Mitre link : CVE-2024-0955
CVE.ORG link : CVE-2024-0955
JSON object : View
Products Affected
tenable
- nessus