ZeroHour

CVE-2024-9158

CVSS 3.1
4.6 medium
EPSS
<1%p24
Published
()
Modified
Description

A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.

Vendors
tenable
Products
nessus network monitor
Weakness
CWE-79
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.