An XSS issue has been found in welcome.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1.x before 8.1R12, 8.2.x before 8.2R9, and 8.3.x before 8.3R3 due to one of the URL parameters not being sanitized properly.
References
Link | Resource |
---|---|
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43730/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-06-28 11:15
Updated : 2019-07-08 07:46
NVD link : CVE-2018-20807
Mitre link : CVE-2018-20807
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
pulsesecure
- pulse_connect_secure