An XSS issue was found with Psaldownload.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.3R2 before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX or PPS 5.2RX.
References
Link | Resource |
---|---|
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43877/ | Vendor Advisory |
http://www.securityfocus.com/bid/109033 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-06-28 11:15
Updated : 2019-07-04 09:15
NVD link : CVE-2018-20814
Mitre link : CVE-2018-20814
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
pulsesecure
- pulse_policy_secure
- pulse_connect_secure