CVE-2019-11507
Ivanti Connect Secure and Policy Secure Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2019-11507 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template. VulnCheck reports CVE-2019-11507 use in known ransomware campaigns.
Description
In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 8, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Connect Secure and Policy SecureBrowse Ivanti / Connect Secure and Policy Secure | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMPulse Secure Pulse Connect Secure - Cross-Site Scripting (Reflected)CVSS 6.1
Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3 contain a reflected cross-site scripting caused by insufficient sanitization on the Application Launcher page, letting attackers execute scripts in the context of the affected page, exploit requires victim to visit a malicious link.
Impact
Attackers can execute arbitrary scripts in the victim's browser, potentially leading to session hijacking or defacement.
Remediation
Update to version 8.3R7.1 or 9.0R3 or later.
Source: ProjectDiscovery