A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary scripts.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16734 | A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary scripts. |
Fixes
Solution
Tenable has released Nessus 10.7.0 to address these issues. The installation files can be obtained from the Tenable Downloads Portal ( https://www.tenable.com/downloads/nessus https://www.tenable.com/downloads/nessus ).
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/tns-2024-01 |
|
History
No history.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-01T18:26:29.995Z
Reserved: 2024-01-26T16:42:07.008Z
Link: CVE-2024-0955
Updated: 2024-08-01T18:26:29.995Z
Status : Modified
Published: 2024-02-07T00:15:55.450
Modified: 2024-11-21T08:47:52.317
Link: CVE-2024-0955
No data.
OpenCVE Enrichment
No data.
EUVD