CVE-2022-27503Cross-site Scripting in Citrix Storefront

Severity
6.1MEDIUMNVD
EPSS
0.6%
top 30.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateApr 14

Description

Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages8 packages

CVEListV5citrix/storefront1912CU5+1
NVDcitrix/storefront_server3.123.12.9000+1

Patches

🔴Vulnerability Details

1
GHSA
GHSA-jp8p-2xpg-mjj3: Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 32022-04-14

📋Vendor Advisories

2
Citrix
CVE-2022-27503: Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU92022-04-13
Citrix
Citrix StoreFront Security Bulletin for CVE-2022-27503