XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, and 5.2RX before 5.2R12.1.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101 | vendor advisory |
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/ | vendor advisory |
http://www.securityfocus.com/bid/108073 | broken link third party advisory vdb entry |
https://www.kb.cert.org/vuls/id/927237 | third party advisory us government resource |