An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-10-27T04:10:54

Updated: 2024-08-04T13:15:20.466Z

Reserved: 2020-06-26T00:00:00

Link: CVE-2020-15352

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-10-27T05:15:12.787

Modified: 2024-02-27T21:04:17.560

Link: CVE-2020-15352

cve-icon Redhat

No data.