CVE-2023-38551

Publication date

2024-05-31 17:38:31

Family

hackerone

State

PUBLISHED

Description

A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.