5.9
CVSSv3

CVE-2020-13407

Published: 09/02/2021 Updated: 08/03/2021
CVSS v2 Base Score: 2.3 | Impact Score: 2.9 | Exploitability Score: 4.4
CVSS v3 Base Score: 5.9 | Impact Score: 3.7 | Exploitability Score: 1.7
VMScore: 205
Vector: AV:A/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or also later by different users). Both stored, and reflected payloads are triggerable by admin, so malicious non-authenticated user could get admin level access. Even malicious low-privileged user can inject XSS, which can be executed by admin, potentially elevating privileges and obtaining admin access. (issue 1 of 3)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tufin securetrack