Citrix NetScaler ADC and NetScaler Gateway contain a reflected cross-site scripting vulnerability when the appliance is configured as a Gateway or AAA virtual server. The vulnerability exists in the SAML response handling mechanism, allowing an attacker to inject malicious JavaScript code through specially crafted RelayState parameters.
An attacker exploiting this vulnerability can craft malicious links that when clicked, can redirect the victim to a malicious site or execute malicious JavaScript code within the victim's browser. This leads to potential theft of sensitive information, session hijacking, defacement of websites, or other unwanted actions conducted on behalf of the user.
Upgrade to the latest version of Citrix NetScaler ADC and Gateway

You can search and find all vulnerabilities
