CVE-2017-11195
Last modified
CVE-2017-11195 is a vulnerability of currently unknown severity. Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME element, if the value contains two quotes. EPSS estimates a 0.90% chance of exploitation in the next 30 days.
Description
Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME element, if the value contains two quotes. It properly sanitizes quotes and tags, so one cannot simply close the src with a quote and inject after that. However, an attacker can use javascript: or data: to abuse this.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pulsesecure | Pulse Connect Secure | 8.3r1.0 |
References
- https://twitter.com/sxcurity/status/884556905145937921Third Party Advisory
- https://twitter.com/sxcurity/status/884556905145937921Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-11195?
How severe is CVE-2017-11195?
How do I fix CVE-2017-11195?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-11189unrarlib.c in unrar-free 0.0.1 might allow remote attackers …6.5
- CVE-2017-1119IBM Marketing Operations 9.1.0, 9.1.2, and 10.1 could allow …4.3
- CVE-2017-11190unrarlib.c in unrar-free 0.0.1, when _DEBUG_LOG mode is enab…
- CVE-2017-11191FreeIPA 4.x with API version 2.213 allows a remote authentic…
- CVE-2017-11193Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the pane…
- CVE-2017-11194Pulse Connect Secure 8.3R1 has Reflected XSS in adminserverc…
- CVE-2017-11196Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logou…
- CVE-2017-11197In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a…7.8
- CVE-2017-11198Cross-site scripting (XSS) vulnerability in /application/lib…
- CVE-2017-1120IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site…
- CVE-2017-11200SQL Injection exists in FineCMS through 2017-07-12 via the a…
- CVE-2017-11201application/core/controller/images.php in FineCMS through 20…
Are you affected by CVE-2017-11195?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
