标题:Citrix Systems StoreFront Server 跨站脚本漏洞 (CVE-2023-5914) Description:Citrix Systems StoreFront Server是美国思杰系统(Citrix Systems)公司的是Xen虚拟化中作为身份验证和交付管理过程中不可缺少的组件。 Citrix Systems StoreFront Server 存在跨站脚本漏洞,该漏洞源于存在跨站脚本(XSS)漏洞。受影响的产品和版本:Citrix StoreFront 2308.1之前版本,Citrix StoreFront 2311之前版本,1912 LTSR CU8 hotfix 3.22.8001.2之前版本,22
Description
Reflected Cross-Site Scripting issue which is exploitable without authentication. This vulnerability was exploitable through coercing an error message during an XML parsing procedure in the SSO flow.