CVE-2023-24488

MEDIUM EXPLOITED NUCLEI

Citrix ADC/Gateway - XSS

Title source: llm

Description

Cross site scripting vulnerability in Citrix ADC and Citrix Gateway  in allows and attacker to perform cross site scripting

Exploits (8)

nomisec SCANNER 14 stars
by securitycipher · client-side
https://github.com/securitycipher/CVE-2023-24488
nomisec WORKING POC 9 stars
by SirBugs · client-side
https://github.com/SirBugs/CVE-2023-24488-PoC
nomisec SCANNER 1 stars
by NSTCyber · poc
https://github.com/NSTCyber/CVE-2023-24488-SIEM-Sigma-Rule
nomisec SCANNER
by raytheon0x21 · poc
https://github.com/raytheon0x21/CVE-2023-24488
vulncheck_xdb SCANNER
client-side
https://github.com/NSTCyber/CVE-2023-24488
vulncheck_xdb WORKING POC
client-side
https://github.com/k00kx/CVE-2023-24488
vulncheck_xdb WRITEUP
client-side
https://github.com/xalgord/My-Methodologies

Nuclei Templates (1)

Citrix Gateway and Citrix ADC - Cross-Site Scripting
MEDIUMby johnk3r,DhiyaneshDk
Shodan: title:"Citrix Gateway" || http.title:"citrix gateway"
FOFA: title="citrix gateway"

Scores

CVSS v3 6.1
EPSS 0.9136
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

VulnCheck KEV 2023-11-15
CWE
CWE-79
Status published
Products (4)
citrix/application_delivery_controller 12.1 - 12.1-55.296 (2 CPE variants)
citrix/application_delivery_controller 12.1 - 12.1-65.35
citrix/application_delivery_controller 13.0 - 13.0-90.11
citrix/gateway 12.1 - 12.1-65.35
Published Jul 10, 2023
Tracked Since Feb 18, 2026