CVE-2020-8191
MEDIUM 6.1EPSS 26.1%
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).
- CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 26.14% chance of exploitation in the next 30 days, 98th percentile
- Nuclei
- medium · CWE-79
- Published
- 2020-07-10
- Updated
- 2024-08-04
Nuclei templates (1)
Exploit collections (2)
- chaitin/xray/blob/master/pocs/citrix-cve-2020-8191-xss.yml
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2020/CVE-2020-8191.yaml