CVE-2023-6184

MEDIUM EXPLOITED

Citrix Virtual Apps and Desktops - Cross-Site Scripting

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-6184 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

Scores

CVSS v3 5.0
EPSS 0.4661
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2025-07-18
CWE
CWE-79 CWE-913
Status published
Products (3)
citrix/virtual_apps_and_desktops 1912 (9 CPE variants)
citrix/virtual_apps_and_desktops 2203 (4 CPE variants)
citrix/virtual_apps_and_desktops < 2311
Published Jan 18, 2024
Tracked Since Feb 18, 2026