CVE-2019-11543
Description
XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, and 5.2RX before 5.2R12.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cross-site scripting vulnerability in the admin web console of Pulse Secure products allows remote attackers to inject arbitrary web script or HTML.
Vulnerability
CVE-2019-11543 is a cross-site scripting (XSS) vulnerability in the admin web console of Pulse Secure Pulse Connect Secure (PCS) versions 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.1RX before 8.1R15.1, and Pulse Policy Secure versions 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, and 5.2RX before 5.2R12.1 [1]. The vulnerability allows an attacker to inject arbitrary web script or HTML via a crafted request to the admin console.
Exploitation
An attacker must have network access to the admin web console. No authentication is required to trigger the XSS, as the vulnerability is pre-authentication. The attacker can craft a malicious URI that, when visited by an administrator, executes the injected script in the context of the admin session [1].
Impact
Successful exploitation could allow the attacker to execute arbitrary JavaScript in the context of the admin's browser session, potentially leading to session hijacking, defacement, or further compromise of the Pulse Secure appliance [1]. The attacker could perform actions with the privileges of the administrator.
Mitigation
Pulse Secure has released patches for all affected versions: PCS 9.0R3.4, 8.3R7.1, and 8.1R15.1; Pulse Policy Secure 9.0R3.2, 5.4R7.1, and 5.2R12.1. No workarounds are available; applying the vendor-supplied patches is the only mitigation [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <9.0R3.4, <8.3R7.1, <8.1R15.1
- Range: <9.0R3.2, <5.4R7.1, <5.2R12.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.kb.cert.org/vuls/id/927237mitrethird-party-advisoryx_refsource_CERT-VN
- www.securityfocus.com/bid/108073mitrevdb-entryx_refsource_BID
- kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101mitrex_refsource_CONFIRM
- kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.