---
id: CVE-2018-1155
title: >-
  In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue
  could allow an authenticated attacker to inject JavaScript code into an image
  filename parameter within the Reports feature area
summary: >-
  In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue
  could allow an authenticated attacker to inject JavaScript code into an image
  filename parameter within the Reports feature area. Properly updated input
  valida…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: tenable
product: security_center
affected:
  - security_center < 5.7.0
patched:
  - security_center 5.7.0
published: '2018-08-02'
updated: '2026-08-17'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-1155'
references:
  - url: 'http://www.securitytracker.com/id/1041431'
    label: vulnreport@tenable.com
  - url: 'https://www.tenable.com/security/tns-2018-11'
    label: vulnreport@tenable.com
  - url: 'http://www.securitytracker.com/id/1041431'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2018-11'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00765
epssPercentile: 0.53489
ingestedAt: '2026-08-17T14:55:58.740Z'
---

## Overview

In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to inject JavaScript code into an image filename parameter within the Reports feature area. Properly updated input validation techniques have been implemented to correct this issue.

## Affected

- `security_center < 5.7.0`

## Remediation

Upgrade past the affected range:

- `security_center 5.7.0`
