CVE-2015-2839: XSS
Published Apr 3, 2015
·Updated
The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the filename JSON member in params/xenhotfix/0 to nitro/v1/config/xenhotfix.
Affected Software
1 affected component
Citrix NetScaler=10.5
Event History
Apr 3, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2839?
CVE-2015-2839 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-2839?
To fix CVE-2015-2839, it is recommended to update Citrix NetScaler to a version that is patched for this vulnerability.
3
What type of attack does CVE-2015-2839 allow?
CVE-2015-2839 allows remote attackers to conduct cross-site scripting (XSS) attacks.
4
What version of Citrix NetScaler is affected by CVE-2015-2839?
CVE-2015-2839 affects Citrix NetScaler version 10.5 before build 52.3nc.
5
What specific endpoint is exploited in CVE-2015-2839?
CVE-2015-2839 exploits the params/xen_hotfix/0 to nitro/v1/config/xen_hotfix endpoint.