First published: Fri Apr 17 2020(Updated: )
Stored XSS in Tenable.Sc before 5.14.0 could allow an authenticated remote attacker to craft a request to execute arbitrary script code in a user's browser session. Updated input validation techniques have been implemented to correct this issue.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tenable Tenable.sc | =5.14.0 | |
Tenable Tenable.sc | =5.14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-5737.
The severity of CVE-2020-5737 is medium with a CVSS score of 5.4.
The affected software is Tenable.sc versions 5.14.0 and 5.14.1.
An authenticated remote attacker can exploit this vulnerability by crafting a request to execute arbitrary script code in a user's browser session.
Yes, updated input validation techniques have been implemented in Tenable.sc 5.14.0 and 5.14.1 to correct this issue.