First published: Fri Apr 03 2015(Updated: )
Cross-site scripting (XSS) vulnerability in help/rt/large_search.html in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to inject arbitrary web script or HTML via the searchQuery parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix NetScaler SD-WAN | =10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2840 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting (XSS) attacks.
To mitigate CVE-2015-2840, update Citrix NetScaler to version 10.5 build 52.3nc or later.
CVE-2015-2840 affects Citrix NetScaler versions prior to 10.5 build 52.3nc.
CVE-2015-2840 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts.
Yes, CVE-2015-2840 can be exploited remotely by attackers through the searchQuery parameter in the affected application.