Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://support.citrix.com/article/CTX583930/citrix-session-recording-security-bulletin-for-cve20236184 | vendor advisory |