CVE-2021-22936
16.08.2021, 19:15
A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter.
Vendor | Product | Version |
---|---|---|
ivanti | connect_secure | 9.1 |
ivanti | connect_secure | 9.1:r1.0 |
ivanti | connect_secure | 9.1:r10.0 |
ivanti | connect_secure | 9.1:r11.0 |
ivanti | connect_secure | 9.1:r2.0 |
ivanti | connect_secure | 9.1:r3.0 |
ivanti | connect_secure | 9.1:r4.0 |
ivanti | connect_secure | 9.1:r5.0 |
ivanti | connect_secure | 9.1:r6.0 |
ivanti | connect_secure | 9.1:r7.0 |
ivanti | connect_secure | 9.1:r8.0 |
ivanti | connect_secure | 9.1:r9.0 |
pulsesecure | pulse_connect_secure | 𝑥 < 9.1 |
𝑥
= Vulnerable software versions