CVE-2023-24488

Cross site scripting

Basic Information

CVE State
PUBLISHED
Reserved Date
January 24, 2023
Published Date
July 10, 2023
Last Updated
October 25, 2024
Vendor
Citrix
Product
Citrix ADC and Citrix Gateway 
Description
Cross site scripting vulnerability in Citrix ADC and Citrix Gateway  in allows and attacker to perform cross site scripting

CVSS Scores

CVSS v3.1

6.1 - MEDIUM

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS Score

Score
90.75% (Percentile: 99.58%) as of 2025-04-29

SSVC Information

Exploitation
none
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (added 2025-04-28 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-04-28 00:00:00 UTC

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

raytheon0x21/CVE-2023-24488

Type: github • Created: 2023-07-31 11:29:16 UTC • Stars: 0

Tools to perform exploit CVE-2023-24488

securitycipher/CVE-2023-24488

Type: github • Created: 2023-07-04 18:02:50 UTC • Stars: 13

POC for CVE-2023-24488

SirBugs/CVE-2023-24488-PoC

Type: github • Created: 2023-07-01 17:47:17 UTC • Stars: 9

CVE-2023-24488 PoC