CVE-2018-1155
mediumCVSS v3 Base Score
5.4
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.6%
Exploitation probability in 30 days
Top 56% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Confidentiality
Low
Integrity
Low
Availability
None
Published: August 2, 2018 (2958 days ago)
Last Modified: August 17, 2026
Vendor: Tenable
Source: NVD
Vulnerability Report
Generated by CyberWatcher
Description
In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to inject JavaScript code into an image filename parameter within the Reports feature area. Properly updated input validation techniques have been implemented to correct this issue.
CWE
CWE-79Affected Products
tenable security center