CVE-2016-4945: XSS
Cross-site scripting (XSS) vulnerability in vpn/js/gatewayloginformview.js in Citrix NetScaler Gateway 11.0 before Build 66.11 allows remote attackers to inject arbitrary web script or HTML via the NSCTMAC cookie.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4945?
CVE-2016-4945 has a critical severity rating as it allows remote attackers to execute arbitrary scripts on victim browsers.
How do I fix CVE-2016-4945?
To fix CVE-2016-4945, upgrade your Citrix NetScaler Gateway to release 11.0 Build 66.11 or later.
Which versions are affected by CVE-2016-4945?
CVE-2016-4945 affects Citrix NetScaler Gateway versions prior to Build 66.11, specifically those below Build 65.35.
What type of vulnerability is CVE-2016-4945?
CVE-2016-4945 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
Can CVE-2016-4945 be exploited without authentication?
Yes, CVE-2016-4945 can potentially be exploited by unauthenticated users through the NSC_TMAC cookie.