CVE-2018-1155EPSS p45.2%

CVE-2018-1155CVE-2018-1155

tenable / security_center

Description

In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to inject JavaScript code into an image filename parameter within the Reports feature area. Properly updated input validation techniques have been implemented to correct this issue.

Scoring

CVSS 5.4 ()
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS0.57% probability of exploitation · percentile 45.2% · 2026-10-05T12:00:23Z
Last modified2026-08-17
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.