RULE(RULE ID:336126)

Rule General Information
Release Date: 2021-12-31
Rule Name: Citrix Systems Cross Site Scripting Vulnerability (CVE-2020-8191)
Severity:
CVE ID:
Rule Protection Details
Description: Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference: https://support.citrix.com/article/CTX276688
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://support.citrix.com/article/CTX276688