CVE-2018-1142: XSS
Published Mar 28, 2018
·Updated
Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability. Utilizing a specially crafted request, an authenticated attacker could potentially execute arbitrary JavaScript code by manipulating certain URL parameters related to offline plugins.
Affected Software
1 affected component
Tenable Appliance<=4.6.1
Remediation
Patch Available
Event History
Mar 28, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1142?
CVE-2018-1142 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2018-1142?
To fix CVE-2018-1142, upgrade your Tenable Appliance to version 4.6.2 or later.
3
What kind of vulnerability is CVE-2018-1142?
CVE-2018-1142 is an XSS (Cross-Site Scripting) vulnerability.
4
Who is affected by CVE-2018-1142?
CVE-2018-1142 affects Tenable Appliance versions 4.6.1 and earlier.
5
What can an attacker achieve with CVE-2018-1142?
An attacker can execute arbitrary JavaScript code by manipulating certain URL parameters.