CVE-2020-5765: XSS
Published Jul 15, 2020
·Updated
Nessus 8.10.0 and earlier were found to contain a Stored XSS vulnerability due to improper validation of input during scan configuration. An authenticated, remote attacker could potentially exploit this vulnerability to execute arbitrary code in a user's session. Tenable has implemented additional input validation mechanisms to correct this issue in Nessus 8.11.0.
Affected Software
1 affected component
Tenable Nessus<=8.10.0
Event History
Jul 15, 2020
CVE Published
via MITRE·12:18 PM
Data Sourced
via MITRE·12:18 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security flaw?
The vulnerability ID of this security flaw is CVE-2020-5765.
2
What is the severity level of CVE-2020-5765?
The severity level of CVE-2020-5765 is medium.
3
What is the affected software by CVE-2020-5765?
The affected software by CVE-2020-5765 is Nessus 8.10.0 and earlier.
4
What is the potential impact of CVE-2020-5765?
The potential impact of CVE-2020-5765 is the execution of arbitrary code in a user's session.
5
Is there a fix or patch available for CVE-2020-5765?
Yes, Tenable has implemented additional measures to address this vulnerability.