Lucene search

K
cve[email protected]CVE-2022-27503
HistoryApr 13, 2022 - 6:15 p.m.

CVE-2022-27503

2022-04-1318:15:14
CWE-79
web.nvd.nist.gov
52
cve
2022
27503
xss
citrix storefront
vulnerability
security
nvd

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

31.3%

Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9

Affected configurations

NVD
Node
citrixstorefront_serverRange3.123.12.9000
OR
citrixstorefront_serverRange19121912.0.5000ltsr

CNA Affected

[
  {
    "product": "StoreFront",
    "vendor": "Citrix",
    "versions": [
      {
        "lessThan": "CU5",
        "status": "affected",
        "version": "1912",
        "versionType": "custom"
      },
      {
        "lessThan": "CU9",
        "status": "affected",
        "version": "3.12",
        "versionType": "custom"
      }
    ]
  }
]

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

31.3%

Related for CVE-2022-27503