First published: Fri May 02 2014(Updated: )
Cross-site scripting (XSS) vulnerability in Citrix NetScaler Gateway (formerly Citrix Access Gateway Enterprise Edition) 9.x before 9.3.66.5 and 10.x before 10.1.123.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix NetScaler Access Gateway Firmware | =9.3 | |
Citrix NetScaler Access Gateway Firmware | =9.3.61.5 | |
Citrix NetScaler Access Gateway Firmware | =9.3.62.4 | |
Citrix NetScaler Access Gateway Firmware | =10.0 | |
Citrix NetScaler Access Gateway Firmware | =10.0.74.4 | |
Citrix NetScaler Access Gateway Firmware | =10.1 | |
Citrix NetScaler Access Gateway Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1899 is categorized as a medium-severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2014-1899, upgrade to Citrix NetScaler Gateway version 9.3.66.5 or later, or 10.1.123.9 or later.
CVE-2014-1899 affects Citrix NetScaler Gateway versions 9.x before 9.3.66.5 and 10.x before 10.1.123.9.
CVE-2014-1899 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Yes, CVE-2014-1899 can compromise user sessions and lead to unauthorized actions by exploiting XSS techniques.