PT-2021-9563 · Tufin · Tufin Securechange

Published

2021-01-20

·

Updated

2021-01-23

·

CVE-2020-13133

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tufin SecureChange versions prior to R19.3 HF3 Tufin SecureChange versions prior to R20-1 HF1
Description The issue is related to stored XSS, which can be exploited by unauthenticated users, but requires admin privileges to store the XSS payload. All TOS versions with SecureChange deployments prior to the fixed versions are affected.
Recommendations For versions prior to R19.3 HF3, update to R19.3 HF3 or later to resolve the issue. For versions prior to R20-1 HF1, update to R20-1 HF1 or later to resolve the issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13133

Affected Products

Tufin Securechange