PT-2020-18659 · Tenable · Tenable.Sc

Mateusz Dabrowski

·

Published

2020-04-17

·

Updated

2020-04-23

·

CVE-2020-5737

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tenable.Sc versions prior to 5.14.0
Description The issue allows an authenticated remote attacker to execute arbitrary script code in a user's browser session through a stored XSS attack. Updated input validation techniques have been implemented to correct this issue.
Recommendations For versions prior to 5.14.0, update to version 5.14.0 or later to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5737

Affected Products

Tenable.Sc