CVE-2023-38551
Severity CVSS v4.0:
Pending analysis
Type:
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')
Publication date:
31/05/2024
Last modified:
27/03/2025
Description
A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.
Impact
Base Score 3.x
8.20
Severity 3.x
HIGH



