PT-2021-9604 · Tufin · Tufin Securetrack

Published

2021-02-09

·

Updated

2021-03-08

·

CVE-2020-13408

CVSS v3.1

5.9

Medium

VectorAV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tufin SecureTrack versions prior to R20-2 GA
Description The issue concerns reflected and stored XSS, where an injected value is both reflected back to the user and stored in the database. This stored value can be triggered again by the same victim or by different users later on. Both types of payloads can be triggered by an admin, allowing a malicious non-authenticated user to potentially gain admin-level access. Additionally, a malicious low-privileged user can inject XSS, which can be executed by an admin, potentially leading to elevated privileges and admin access.
Recommendations For Tufin SecureTrack versions prior to R20-2 GA, update to version R20-2 GA or later to resolve the issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13408

Affected Products

Tufin Securetrack