CVE-2019-11507: XSS
In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-11507?
CVE-2019-11507 is a vulnerability in Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3 that allows for cross-site scripting (XSS) attacks on the Application Launcher page.
How severe is CVE-2019-11507?
CVE-2019-11507 has a severity score of 6.1, which is considered medium.
How does CVE-2019-11507 affect Pulse Connect Secure?
CVE-2019-11507 affects Pulse Connect Secure versions 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3.
How can CVE-2019-11507 be exploited?
CVE-2019-11507 can be exploited through cross-site scripting (XSS) attacks on the Application Launcher page of Pulse Connect Secure.
Are there any references or resources available for CVE-2019-11507?
Yes, you can find more information about CVE-2019-11507 at the following sources: [1] SecurityFocus, [2] Devco.re blog, [3] Black Hat presentation on infiltrating corporate intranets.