Vulnerability record · CVE-2023-6184 · published 18 January 2024
CVE-2023-6184: Citrix Session Recording Cross-Site Scripting
Citrix · Virtual Apps And Desktops
CVE-2023-6184 is a cross-site scripting flaw in Citrix Session Recording, part of Citrix Virtual Apps and Desktops. The record gives only a one-line description, so the exact vulnerable component and input path are not specified. It matters because a high-privileged user can inject script that executes in another user's session context.
Description
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.2 with high EPSS and full C/I/A impact, though exploitation requires an already high-privileged account.
What it is
CVE-2023-6184 is a cross-site scripting flaw in Citrix Session Recording, part of Citrix Virtual Apps and Desktops. The record gives only a one-line description, so the exact vulnerable component and input path are not specified. It matters because a high-privileged user can inject script that executes in another user's session context.
Impact
An attacker with the required privileges can execute script in a victim's browser session, potentially stealing session data or acting as that user. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reachable over the network (AV:N) with no user interaction (UI:N), but it requires high privileges (PR:H), meaning the attacker must already hold an administrative or similarly elevated account. The description does not state which Session Recording interface or parameter is the injection point.
Exploitation
Not listed in CISA KEV and no ransomware use is documented. EPSS is 0.4661 (98.8th percentile), indicating a high predicted likelihood of exploitation, but the only references are vendor advisories and no public exploit is confirmed in the record.
What to do
- Apply the Citrix security update in bulletin CTX583930 for Session Recording.
- Restrict Session Recording administrative access to the minimum set of trusted accounts.
- Validate and encode user-supplied input in Session Recording views and parameters.
- Monitor vendor advisory for updated affected version details and re-check exposure.
Detection
- Review Session Recording web logs for script payloads or unexpected markup in request parameters.
- Alert on anomalous administrative sessions or privilege use against Session Recording endpoints.
- Inspect browser or proxy logs for reflected script content originating from Session Recording URLs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-6184 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-6184), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.