CVE-2017-11195
MEDIUMPulsesecure Pulse Connect Secure - XSS
Title source: ruleDescription
Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME element, if the value contains two quotes. It properly sanitizes quotes and tags, so one cannot simply close the src with a quote and inject after that. However, an attacker can use javascript: or data: to abuse this.
Scores
CVSS v3
6.1
EPSS
0.0039
EPSS Percentile
59.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
pulsesecure/pulse_connect_secure
n/a/n/a
Published
Jul 12, 2017
Tracked Since
Feb 18, 2026