CVE-2020-5737: XSS
Published Apr 17, 2020
·Updated
Stored XSS in Tenable.Sc before 5.14.0 could allow an authenticated remote attacker to craft a request to execute arbitrary script code in a user's browser session. Updated input validation techniques have been implemented to correct this issue.
Affected Software
2 affected components
Tenable Tenable.Sc=5.14.0
Tenable Tenable.Sc=5.14.1
Remediation
Patch Available
Event History
Apr 17, 2020
CVE Published
via MITRE·06:24 PM
Data Sourced
via MITRE·06:24 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-5737.
2
What is the severity of CVE-2020-5737?
The severity of CVE-2020-5737 is medium with a CVSS score of 5.4.
3
What is the affected software by CVE-2020-5737?
The affected software is Tenable.sc versions 5.14.0 and 5.14.1.
4
How can an attacker exploit this vulnerability?
An authenticated remote attacker can exploit this vulnerability by crafting a request to execute arbitrary script code in a user's browser session.
5
Has this vulnerability been fixed?
Yes, updated input validation techniques have been implemented in Tenable.sc 5.14.0 and 5.14.1 to correct this issue.