Cross Site Scripting Vulnerability in Citrix Session Recording
CVE-2023-6184
5MEDIUM
Key Information:
- Vendor
Cloud Software Group
- Status
- Vendor
- CVE Published:
- 18 January 2024
Badges
🟣 EPSS 26%📰 News Worthy
What is CVE-2023-6184?
A Cross Site Scripting (XSS) vulnerability exists in Citrix Session Recording, which could allow an attacker to inject malicious scripts into the web application. This flaw may lead to unauthorized access to sensitive user data and compromise the integrity of the application. It is essential for organizations utilizing this product to implement appropriate security measures to reduce the risk associated with this vulnerability and protect their users.
Affected Version(s)
Citrix Session Recording 2311 Current Release < 0
Citrix Session Recording 1912 LTSR
Citrix Session Recording 2203 LTSR
News Articles
References
EPSS Score
26% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
- 📰
First article discovered by Assetnote
Vulnerability published
Vulnerability Reserved