A reflected cross-site scripting (XSS) issue has been discovered in Citrix StoreFront when it is configured to use SAML authentication. If exploited, this issue would allow an attacker to execute client-side JavaScript in the same context as a legitimate user. This issue has the following identifier:
CVE-ID |
Description |
Type |
Pre-requisites |
CVE-2022-27503 |
Reflected Cross Site Scripting (XSS) |
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
A victim user must have a current session on a StoreFront that has been configured to use SAML authentication |
The issue affects the following supported versions of Citrix StoreFront:
Affected versions of Citrix Storefront are included within the following supported versions of Citrix Virtual Apps and Desktops:
Citrix recommends that affected customers upgrade to a fixed version as their patching schedule allows.
The issue has been addressed in the following supported Citrix StoreFront versions:
The latest versions of Citrix StoreFront can be downloaded from the following location:
https://www.citrix.com/downloads/storefront/
These versions of Citrix StoreFront are included within the following supported versions of Citrix Virtual Apps and Desktops:
The latest versions of Citrix Virtual Apps and Desktops can be downloaded from the following location:
https://www.citrix.com/downloads/citrix-virtual-apps-and-desktops/
A hotfix has been released to address this issue for Citrix StoreFront 3.12 for 7.15 LTSR.
The hotfix for Citrix StoreFront 3.12 for 7.15 LTSR is available at the following location:
https://support.citrix.com/article/CTX446966
Date | Change |
2022-04-12 | Initial Publication |