CVE-2024-1891: Stored Cross Site Scripting
Published Jun 12, 2024
·Updated
A stored cross site scripting vulnerability exists in Tenable Security Center where an authenticated, remote attacker could inject HTML code into a web application scan result page.
Affected Software
1 affected component
Tenable Security Center<6.4.0
Remediation
Information
Tenable has released Security Center 6.4.0 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/security-center
Event History
Jun 12, 2024
CVE Published
via MITRE·03:56 PM
Data Sourced
via MITRE·03:56 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-1891?
CVE-2024-1891 has been assigned a high severity rating due to its potential to allow authenticated attackers to execute cross-site scripting attacks.
2
How do I fix CVE-2024-1891?
To mitigate CVE-2024-1891, it is recommended to upgrade Tenable Security Center to a version above 6.4.0.
3
Who is affected by CVE-2024-1891?
CVE-2024-1891 affects all versions of Tenable Security Center prior to 6.4.0.
4
What type of vulnerability is CVE-2024-1891?
CVE-2024-1891 is a stored cross-site scripting (XSS) vulnerability.
5
Can CVE-2024-1891 be exploited remotely?
Yes, CVE-2024-1891 can be exploited by an authenticated remote attacker.