CVE-2024-1471: HTML Injection Vulnerability
An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tenable Security Centerto a version that resolves this vulnerability.Fixed in 6.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1471?
CVE-2024-1471 is classified as a critical vulnerability due to its potential for allowing HTML injection attacks.
How do I fix CVE-2024-1471?
To mitigate CVE-2024-1471, ensure that you update Tenable Security Center to a version higher than 6.3.0.
Who is affected by CVE-2024-1471?
CVE-2024-1471 affects users of Tenable Security Center versions up to 6.3.0 with administrator privileges.
What types of attacks can CVE-2024-1471 lead to?
CVE-2024-1471 can lead to HTML redirection attacks, allowing attackers to redirect users to malicious sites.
Is user authentication required to exploit CVE-2024-1471?
Yes, CVE-2024-1471 can only be exploited by authenticated users with administrator privileges.