First published: Wed Jul 19 2023(Updated: )
Reflected Cross-Site Scripting (XSS)
Credit: secure@citrix.com secure@citrix.com
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix NetScaler Application Delivery Controller | >=12.1<12.1-55.297 | |
Citrix NetScaler Application Delivery Controller | >=12.1<12.1-55.297 | |
Citrix NetScaler Application Delivery Controller | >=13.0<13.0-91.13 | |
Citrix NetScaler Application Delivery Controller | >=13.1<13.1-37.159 | |
Citrix NetScaler Application Delivery Controller | >=13.1<13.1-49.13 | |
Citrix NetScaler Application Delivery Controller | =11.1-65.22 | |
Citrix NetScaler Gateway | >=13.0<13.0-91.13 | |
Citrix NetScaler Gateway | >=13.1<13.1-49.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3466 is a vulnerability known as Reflected Cross-Site Scripting (XSS).
The severity of CVE-2023-3466 is high with a CVSS score of 6.1.
The Citrix Netscaler Application Delivery Controller and Citrix Netscaler Gateway versions 11.1-65.22, 12.1-55.297, 13.0-91.13, and 13.1-49.13 are affected.
Follow the instructions provided in the Citrix security bulletin at the following link: [link](https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467).
The Common Weakness Enumeration (CWE) for CVE-2023-3466 is CWE-79 (Improper Neutralization of Input During Web Page Generation) and CWE-20 (Improper Input Validation).