Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update CVE-2023-24488 - Avoid false positives #80

Merged
merged 1 commit into from
Aug 10, 2023
Merged

Update CVE-2023-24488 - Avoid false positives #80

merged 1 commit into from
Aug 10, 2023

Commits on Aug 9, 2023

  1. Update CVE-2023-24488 - Citrix Gateway Open Redirect and XSS.bcheck

    This will avoid false positives due to the fact that some 404 status pages returns the introduced parameter encoding the "<" and ">" characters, but not the ".", so "document.cookie" appears but the rest of the payload is as introduced, "%3Cscript%3Ealert(document.cookie)%3C/script%3e".
    whoissecure authored Aug 9, 2023
    Configuration menu
    Copy the full SHA
    91c0590 View commit details
    Browse the repository at this point in the history