CVE-2016-4789: XSS
Cross-site scripting (XSS) vulnerability in the system configuration section in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4789?
CVE-2016-4789 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2016-4789?
To fix CVE-2016-4789, upgrade to Pulse Connect Secure version 8.2r1, 8.1r2, 8.0r9, or 7.4r13.4 or later.
Who is affected by CVE-2016-4789?
CVE-2016-4789 affects users of Pulse Connect Secure versions prior to the specified patched versions.
What products are impacted by CVE-2016-4789?
CVE-2016-4789 impacts various versions of Pulse Secure and Ivanti Connect Secure.
Can CVE-2016-4789 lead to unauthorized access?
Yes, CVE-2016-4789 can allow remote attackers to inject arbitrary web scripts or HTML, potentially leading to unauthorized access.