CVE-2016-4790: XSS
Cross-site scripting (XSS) vulnerability in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4790?
CVE-2016-4790 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2016-4790?
To mitigate CVE-2016-4790, update your Pulse Connect Secure or Ivanti Connect Secure software to versions 8.2r1, 8.1r2, 8.0r9, or 7.4r13.4 or later.
Which versions are affected by CVE-2016-4790?
CVE-2016-4790 affects Pulse Connect Secure versions 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4.
What is the impact of CVE-2016-4790?
CVE-2016-4790 allows remote attackers to inject arbitrary web scripts or HTML into the administrative user interface.
Who is vulnerable to CVE-2016-4790?
Organizations using affected versions of Pulse Connect Secure or Ivanti Connect Secure are vulnerable to CVE-2016-4790.