CVE-2023-38551
EUVD-2023-4235031.05.2024, 18:15
A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| ivanti | connect_secure | 𝑥 ≤ 22.7R2 | CNA |
| ivanti | connect_secure | 𝑥 ≤ 22.5R2.2 | CNA |
| ivanti | connect_secure | 𝑥 ≤ 9.1R18.6 | CNA |