6.1

CVE-2018-20807

An XSS issue has been found in welcome.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1.x before 8.1R12, 8.2.x before 8.2R9, and 8.3.x before 8.3R3 due to one of the URL parameters not being sanitized properly.

Data is provided by the National Vulnerability Database (NVD)
IvantiConnect Secure Version8.1 Updater1.0
IvantiConnect Secure Version8.1 Updater1.1
IvantiConnect Secure Version8.1 Updater10.0
IvantiConnect Secure Version8.1 Updater11.0
IvantiConnect Secure Version8.1 Updater11.1
IvantiConnect Secure Version8.1 Updater2.0
IvantiConnect Secure Version8.1 Updater2.1
IvantiConnect Secure Version8.1 Updater3.1
IvantiConnect Secure Version8.1 Updater3.2
IvantiConnect Secure Version8.1 Updater4.0
IvantiConnect Secure Version8.1 Updater4.1
IvantiConnect Secure Version8.1 Updater5.0
IvantiConnect Secure Version8.1 Updater6.0
IvantiConnect Secure Version8.1 Updater7
IvantiConnect Secure Version8.1 Updater7.0
IvantiConnect Secure Version8.1 Updater8.0
IvantiConnect Secure Version8.1 Updater9.0
IvantiConnect Secure Version8.1 Updater9.1
IvantiConnect Secure Version8.1 Updater9.2
IvantiConnect Secure Version8.2 Updater1
IvantiConnect Secure Version8.2 Updater1.0
IvantiConnect Secure Version8.2 Updater1.1
IvantiConnect Secure Version8.2 Updater2.0
IvantiConnect Secure Version8.2 Updater3.0
IvantiConnect Secure Version8.2 Updater3.1
IvantiConnect Secure Version8.2 Updater4.0
IvantiConnect Secure Version8.2 Updater4.1
IvantiConnect Secure Version8.2 Updater5.0
IvantiConnect Secure Version8.2 Updater5.1
IvantiConnect Secure Version8.2 Updater6.0
IvantiConnect Secure Version8.2 Updater7.0
IvantiConnect Secure Version8.2 Updater7.1
IvantiConnect Secure Version8.2 Updater7.2
IvantiConnect Secure Version8.2 Updater8.0
IvantiConnect Secure Version8.2 Updater8.1
IvantiConnect Secure Version8.2 Updater8.2
IvantiConnect Secure Version8.3 Updater1
IvantiConnect Secure Version8.3 Updater2
IvantiConnect Secure Version8.3 Updater2.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.12% 0.315
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.