CVE-2020-8263: XSS
A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) through the CGI file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-8263?
CVE-2020-8263 is a vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 that could allow attackers to conduct Cross-Site Scripting (XSS) through the CGI file.
What software versions are affected by CVE-2020-8263?
The Pulse Secure Desktop Client versions 9.1, up to and including 9.1R8.2, are affected by CVE-2020-8263.
How severe is CVE-2020-8263?
CVE-2020-8263 has a severity rating of 5.4, which is considered medium.
How can attackers exploit CVE-2020-8263?
Attackers can exploit CVE-2020-8263 by conducting Cross-Site Scripting (XSS) attacks through the CGI file in the authenticated user web interface of Pulse Connect Secure.
Where can I find more information about CVE-2020-8263?
You can find more information about CVE-2020-8263 in the Pulse Secure Security Advisory at the following link: https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601