Record summary

CVE-2019-11507 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template. VulnCheck reports CVE-2019-11507 use in known ransomware campaigns.

Description

In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 8, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Connect Secure and Policy Secure

Browse Ivanti / Connect Secure and Policy Secure
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMPulse Secure Pulse Connect Secure - Cross-Site Scripting (Reflected)CVSS 6.1

Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3 contain a reflected cross-site scripting caused by insufficient sanitization on the Application Launcher page, letting attackers execute scripts in the context of the affected page, exploit requires victim to visit a malicious link.

Impact

Attackers can execute arbitrary scripts in the victim's browser, potentially leading to session hijacking or defacement.

Remediation

Update to version 8.3R7.1 or 9.0R3 or later.

WeaknessesCWE-79
Authorstheamanrawat
Template tagscvecve2019pulsesecurexssvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:ivanti:connect_secure:8.3:r1:*:*:*:*:*:*
Shodan: http.html:"welcome.cgi?p=logo"
Shodan: http.title:"ivanti connect secure"
FOFA: body="welcome.cgi?p=logo"
FOFA: title="ivanti connect secure"
Google: intitle:"ivanti connect secure"

Source: ProjectDiscovery

References

8