Record summary

CVE-2023-5914 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

Cross-site scripting (XSS)

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 8, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 18, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List2308 Current Release to < 1affected
2311 Current Release to < 0affected
1912 LTSR to < CU8 hotfix 3.22.8001.2affected
2203 LTSR to < CU4 Update 1affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMCitrix StoreFront - Cross-Site ScriptingCVSS 6.1

Reflected Cross-Site Scripting issue which is exploitable without authentication. This vulnerability was exploitable through coercing an error message during an XML parsing procedure in the SSO flow.

Impact

Unauthenticated attackers can inject malicious JavaScript via reflected XSS during XML parsing in the SSO flow, potentially stealing user credentials or session tokens.

Remediation

Apply Citrix security updates immediately. Update to StoreFront versions 2402, 2203 CU1, 2203 LTSR CU5, 1912 LTSR CU8, or later.

WeaknessesCWE-79
AuthorsDhiyaneshDK
Template tagscvexsscitrixstorefrontcve2023cloudvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:cloud:citrix_storefront:*:*:*:*:ltsr:*:*:*
Shodan: html:"/Citrix/StoreWeb"
Shodan: http.html:"/citrix/storeweb"
FOFA: body="/citrix/storeweb"

Source: ProjectDiscovery

References

2