Security Advisory

CVE-2023-38551

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-05-31 17:38:31
Last updated 2025-03-27 20:43:12
Assigner hackerone
State PUBLISHED

Description

A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.