A CRLF Injection vulnerability in Ivanti Connect Secure ...
High severity
Unreviewed
Published
May 31, 2024
to the GitHub Advisory Database
•
Updated Mar 27, 2025
Description
Published by the National Vulnerability Database
May 31, 2024
Published to the GitHub Advisory Database
May 31, 2024
Last updated
Mar 27, 2025
A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.
References