CVE-2024-9158

A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.
References
Link Resource
https://www.tenable.com/security/tns-2024-17 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:tenable:nessus_network_monitor:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-30 17:15

Updated : 2024-10-07 16:13


NVD link : CVE-2024-9158

Mitre link : CVE-2024-9158

CVE.ORG link : CVE-2024-9158


JSON object : View

Products Affected

tenable

  • nessus_network_monitor
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')