CVE-2020-13407 Information

Description

Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in the value is reflected back to the user but is also stored within the DB and can be later triggered again by the same victim or also later by different users). Both stored and reflected payloads are triggerable by admin so malicious non-authenticated user could get admin level access. Even malicious low-privileged user can inject XSS which can be executed by admin potentially elevating privileges and obtaining admin access. (issue 1 of 3)

CVSS Vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Reference

https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.md

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

LOW

Base Severity

5.9

Share on: