CVE-2023-38551

A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.
Configurations

No configuration.

History

27 Mar 2025, 21:15

Type Values Removed Values Added
CWE CWE-93

21 Nov 2024, 08:13

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de inyección CRLF en Ivanti Connect Secure (9.x, 22.x) permite a un usuario autenticado con altos privilegios inyectar código malicioso en el navegador de una víctima, lo que lleva a un ataque de cross-site scripting.
References () https://forums.ivanti.com/s/article/Security-Advisory-May-2024 - () https://forums.ivanti.com/s/article/Security-Advisory-May-2024 -

31 May 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-31 18:15

Updated : 2025-03-27 21:15


NVD link : CVE-2023-38551

Mitre link : CVE-2023-38551

CVE.ORG link : CVE-2023-38551


JSON object : View

Products Affected

No product.

CWE
CWE-93

Improper Neutralization of CRLF Sequences ('CRLF Injection')