CVE-2018-1142: Tenable Appliance

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability. Utilizing a specially crafted request, an authenticated attacker could potentially execute arbitrary JavaScript code by manipulating certain URL parameters related to offline plugins.

Affected products

  • Tenable Appliance: up to and including 4.6.1

Published 2018-03-28. Last modified 2026-06-17.