CVE-2023-38551

A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.
Configurations

No configuration.

History

27 Mar 2025, 21:15

Type Values Removed Values Added
CWE CWE-93

Information

Published : 2024-05-31 18:15

Updated : 2025-03-27 21:15


NVD link : CVE-2023-38551

Mitre link : CVE-2023-38551

CVE.ORG link : CVE-2023-38551


JSON object : View

Products Affected

No product.

CWE
CWE-93

Improper Neutralization of CRLF Sequences ('CRLF Injection')