CVE-2020-13409 Information
Jun 07, 2022
cve
Description
Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in the value is reflected back to the user but is also stored within the DB and can be later triggered again by the same victim or also later by different users). Both stored and reflected payloads are triggerable by admin so malicious non-authenticated user could get admin level access. Even malicious low-privileged user can inject XSS which can be executed by admin potentially elevating privileges and obtaining admin access. (issue 3 of 3)
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Reference
https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.md
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
5.9
Share on: