CVE-2018-1155

CVE-2018-1155CVE-2018-1155

tenable / security_center

Description

In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to inject JavaScript code into an image filename parameter within the Reports feature area. Properly updated input validation techniques have been implemented to correct this issue.

Scoring

CVSS 5.4 ()
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Last modified2026-08-17
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.