CVE-2017-17947 Information
Feb 14, 2021
cve
Description
A cross site scripting issue has been found in custompage.cgi in Pulse Secure Pulse Connect Secure (PCS) before 8.0R17.0 8.1.x before 8.1R13 8.2.x before 8.2R9 and 8.3.x before 8.3R3 and Pulse Policy Secure (PPS) before 5.2R10 5.3.x before 5.3R9 and 5.4.x before 5.4R3 due to one of the URL parameters not being sanitized. Exploitation does require the user to be logged in as administrator; the issue is not applicable to the end user portal.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Reference
http://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43018
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
4.8
Share on: