ZeroHour

CVE-2017-11196

CVSS 3.0
8.8 high
EPSS
<1%p45
Published
()
Modified
Description

Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logout function of the admin panel is not protected by any CSRF tokens, thus allowing an attacker to logout a user by making them visit a malicious web page.

Vendors
pulsesecure
Products
pulse connect secure
Weakness
CWE-352
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.