{"id":"CVE-2013-5911","title":"Cross-site scripting (XSS) vulnerability in devform.php in Tenable SecurityCenter 4.6 through 4.7 allows remote attackers to inject arbitrary web script or HTML via the message parameter.","summary":"Cross-site scripting (XSS) vulnerability in devform.php in Tenable SecurityCenter 4.6 through 4.7 allows remote attackers to inject arbitrary web script or HTML via the message parameter.","severity":"medium","cvss":4.3,"cvssVector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","cwe":["CWE-79"],"vendor":"tenable","product":"security_center","affected":["security_center = 4.6","security_center = 4.7"],"published":"2013-09-24","updated":"2026-08-17","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2013-5911","references":[{"url":"http://www.osvdb.org/97584","label":"cve@mitre.org"},{"url":"https://discussions.nessus.org/message/22174#22174","label":"cve@mitre.org"},{"url":"http://www.osvdb.org/97584","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://discussions.nessus.org/message/22174#22174","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00931,"epssPercentile":0.58609,"ingestedAt":"2026-08-17T14:55:58.493Z","slug":"CVE-2013-5911","body":"## Overview\n\nCross-site scripting (XSS) vulnerability in devform.php in Tenable SecurityCenter 4.6 through 4.7 allows remote attackers to inject arbitrary web script or HTML via the message parameter.\n\n## Affected\n\n- `security_center = 4.6`\n- `security_center = 4.7`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}