CVE-2017-17947: XSS

Published Jan 16, 2018
·
Updated

A cross site scripting issue has been found in custompage.cgi in Pulse Secure Pulse Connect Secure (PCS) before 8.0R17.0, 8.1.x before 8.1R13, 8.2.x before 8.2R9, and 8.3.x before 8.3R3 and Pulse Policy Secure (PPS) before 5.2R10, 5.3.x before 5.3R9, and 5.4.x before 5.4R3 due to one of the URL parameters not being sanitized. Exploitation does require the user to be logged in as administrator; the issue is not applicable to the end user portal.

Affected Software

4 affected components
PulseSecure Pulse Connect Secure<8.0r17.0
PulseSecure Pulse Connect Secure>=8.1<8.1r13
PulseSecure Pulse Connect Secure>=8.2<=8.2r9
PulseSecure Pulse Connect Secure>=8.3<8.3r3

Event History

Jan 16, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2017-17947?

CVE-2017-17947 has been assigned a medium severity rating based on its potential impact and exploitability.

2

How do I fix CVE-2017-17947?

To address CVE-2017-17947, you should upgrade to the latest versions of Pulse Connect Secure or Pulse Policy Secure as specified in the vendor's advisory.

3

What products are affected by CVE-2017-17947?

CVE-2017-17947 affects multiple versions of Pulse Secure Pulse Connect Secure and Pulse Policy Secure prior to specified versions.

4

What type of vulnerability is CVE-2017-17947?

CVE-2017-17947 is classified as a cross-site scripting (XSS) vulnerability.

5

Can CVE-2017-17947 be exploited remotely?

Yes, CVE-2017-17947 can potentially be exploited remotely, allowing attackers to execute harmful scripts in a user's browser.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203