CVE-2019-3962

Description

Content Injection vulnerability in Tenable Nessus prior to 8.5.0 may allow an authenticated, local attacker to exploit this vulnerability by convincing another targeted Nessus user to view a malicious URL and use Nessus to send fraudulent messages. Successful exploitation could allow the authenticated adversary to inject arbitrary text into the feed status, which will remain saved post session expiration.

Risk Information

Base Score
3.3
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS Score
Exploitation Probability
0.227

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-3961,CVE-2019-3962 are affected in Nessus Agent (x64) 8.4.0Windows
Vulnerabilities CVE-2019-3962 are affected in Nessus Agent (x64) 8.4.9Windows
Vulnerabilities CVE-2019-3961,CVE-2019-3962 are affected in Nessus Agent 8.4.0Windows
Vulnerabilities CVE-2019-3962 are affected in Nessus Agent 8.4.9Windows
Vulnerabilities CVE-2019-3961,CVE-2019-3962 are fixed in Nessus 8.5.0Windows
Vulnerabilities CVE-2019-3961,CVE-2019-3962 are fixed in Tenable Nessus 8.5.0Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-343100Nessus Agent (x64) (10.8.0)
PATCH-343100Nessus Agent (x64) (10.8.0)
PATCH-343099Nessus Agent (10.8.0)
PATCH-343099Nessus Agent (10.8.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234