A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.
2024-09-30T17:15:05.407
2024-10-07T16:13:49.027
Analyzed
CVSSv3.1: 8.4 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | tenable | nessus_network_monitor | < 6.5.0 | Yes |