QID 379323
QID 379323: Citrix StoreFront Cross-Site Scripting (XSS) Vulnerability (CTX583759)
Citrix StoreFront is an enterprise app store for users that aggregates and presents virtual app and desktop resources from on-premises and hybrid deployments delivering a near-native user experience across Citrix Workspace app (formerly Citrix Receiver) on any platform.
A vulnerability has been discovered in Citrix StoreFront, which, if exploited, may result in a Cross-site scripting (XSS) attack.
Affected Versions:
Citrix StoreFront before 2308.1.
Citrix StoreFront before 2311
QID Detection Logic (Authenticated):
This QID checks for the Citrix Storefront registry key and the presence of the CitrixStoreFrontConsole.msc file.
Note: The following versions of the Citrix StoreFront server are also affected but are not checked with this QID due to the absence of a vulnerable target in our labs
Citrix StoreFront 1912 LTSR before CU8 hotfix 3.22.8001.2
Citrix StoreFront 2203 LTSR before CU4 Update 1
Successful exploitation of the vulnerability may allow an attacker to perform a Cross-site scripting (XSS) attack.
- CTX583759 -
support.citrix.com/article/CTX583759/
CVEs related to QID 379323
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CTX583759 |
|