CVE-2023-5914
cloud citrix_storefront Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Record summary
CVE-2023-5914 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
Cross-site scripting (XSS)
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 8, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 18, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Citrix StoreFrontBrowse Cloud Software Group / Citrix StoreFrontDefault status: unaffected | CVE List | 2308 Current Release to < 1 | affected |
| 2311 Current Release to < 0 | affected | ||
| 1912 LTSR to < CU8 hotfix 3.22.8001.2 | affected | ||
| 2203 LTSR to < CU4 Update 1 | affected | ||
citrix_storefrontBrowse cloud / citrix_storefront | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMCitrix StoreFront - Cross-Site ScriptingCVSS 6.1
Reflected Cross-Site Scripting issue which is exploitable without authentication. This vulnerability was exploitable through coercing an error message during an XML parsing procedure in the SSO flow.
Impact
Unauthenticated attackers can inject malicious JavaScript via reflected XSS during XML parsing in the SSO flow, potentially stealing user credentials or session tokens.
Remediation
Apply Citrix security updates immediately. Update to StoreFront versions 2402, 2203 CU1, 2203 LTSR CU5, 1912 LTSR CU8, or later.
Source: ProjectDiscovery