PT-2021-9605 · Tufin · Tufin Securetrack

Published

2021-02-09

·

Updated

2021-03-08

·

CVE-2020-13409

CVSS v3.1

5.9

Medium

VectorAV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tufin SecureTrack versions prior to R20-2 GA
Description The issue concerns reflected and stored Cross-Site Scripting (XSS) in Tufin SecureTrack. This allows a malicious non-authenticated user to potentially gain admin-level access. Both stored and reflected payloads can be triggered by an admin, and even a low-privileged user can inject XSS, which can be executed by an admin, potentially elevating privileges and obtaining admin access.
Recommendations For versions prior to R20-2 GA, update to R20-2 GA or later to resolve the issue. As a temporary workaround, consider restricting access to areas where XSS can be injected to minimize the risk of exploitation. Avoid using the application with admin privileges until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13409

Affected Products

Tufin Securetrack