Files
CVEs-PoC/2020/CVE-2020-8256.md
T
2024-05-25 21:48:12 +02:00

19 lines
903 B
Markdown

### [CVE-2020-8256](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8256)
![](https://img.shields.io/static/v1?label=Product&message=Pulse%20Connect%20Secure&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=XML%20External%20Entities%20(XXE)%20(CWE-611)&color=brighgreen)
### Description
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.
### POC
#### Reference
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44588
- https://www.gosecure.net/blog/2020/11/13/forget-your-perimeter-part-2-four-vulnerabilities-in-pulse-connect-secure/
#### Github
- https://github.com/Live-Hack-CVE/CVE-2020-8256