Vulnerability record · CVE-2023-5914 · published 17 January 2024
CVE-2023-5914: Citrix StoreFront cross-site scripting flaw
Cloud · Citrix Storefront
CVE-2023-5914 is a cross-site scripting (XSS) vulnerability in Citrix StoreFront, classified as CWE-79. The record gives no detail on the vulnerable endpoint or input, but XSS in a storefront web component matters because it can run script in the context of an authenticated user's session.
Description
Cross-site scripting (XSS)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityThe CVSS score is only medium (6.1), but the very high EPSS percentile and the fact that StoreFront is an internet-facing authentication portal raise the practical risk.
What it is
CVE-2023-5914 is a cross-site scripting (XSS) vulnerability in Citrix StoreFront, classified as CWE-79. The record gives no detail on the vulnerable endpoint or input, but XSS in a storefront web component matters because it can run script in the context of an authenticated user's session.
Impact
An attacker can execute script in a victim's browser session, potentially stealing session data or performing actions as the victim. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R), consistent with a reflected or DOM-based XSS delivered to a victim. No authentication is needed to trigger the vector, though the victim is likely an authenticated StoreFront user.
Exploitation
Not listed in CISA KEV and no public exploit references are provided; EPSS is high at 0.73142 (99.4th percentile), suggesting elevated predicted exploitation activity despite the absence of confirmed in-the-wild use.
What to do
- Apply the Citrix StoreFront security update referenced in vendor bulletin CTX583759.
- If immediate patching is not possible, restrict network exposure of StoreFront and review Citrix guidance for interim mitigations.
- Enforce output encoding and input validation on StoreFront customizations and any user-supplied content rendered in the UI.
- Deploy a web application firewall with XSS rules in front of StoreFront as a compensating control.
- Educate StoreFront users on phishing links that could deliver the XSS payload.
Detection
- Monitor web and proxy logs for script tags or encoded script payloads in requests to StoreFront URLs.
- Alert on anomalous JavaScript execution or unexpected outbound requests from StoreFront user sessions.
- Review StoreFront and IIS logs for suspicious query strings or reflected input patterns tied to XSS attempts.
- Correlate unusual session activity or credential use following a user clicking a crafted StoreFront link.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-5914 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-5914), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.