CVE-2016-1000028: XSS
Published Dec 27, 2019
·Updated
Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would only potentially impact other admins. (Tenable ID 5198).
Affected Software
1 affected component
Tenable Nessus<6.8.0
Event History
Dec 27, 2019
CVE Published
via MITRE·02:19 PM
Data Sourced
via MITRE·02:19 PM
Description
Frequently Asked Questions
1
What is CVE-2016-1000028?
CVE-2016-1000028 is a vulnerability in Tenable Nessus before version 6.8 that allows stored cross-site scripting (XSS) attacks.
2
How severe is CVE-2016-1000028?
CVE-2016-1000028 has a severity keyword of 'medium' and a severity value of 4.8.
3
How does CVE-2016-1000028 impact Tenable Nessus?
CVE-2016-1000028 requires admin-level authentication to the Nessus UI and would only potentially impact other admins.
4
What is the affected software version and vendor of CVE-2016-1000028?
CVE-2016-1000028 affects Tenable Nessus before version 6.8.
5
How can I fix CVE-2016-1000028?
To fix CVE-2016-1000028, upgrade Tenable Nessus to version 6.8 or later.