Aug. 28, 2023, 6:23 p.m. | Jimi Sebree

Tenable Research Advisories www.tenable.com

Citrix ShareFile Reflected XSS on Login Page

A security-related issue with Citrix ShareFile login pages has been discovered. The issue is a reflected cross-site scripting attack which could allow a malicious actor to steal login credentials, tokens, execute code in the context of a victim's browser, or perform a variety of other malicious actions.


Citrix has elected not to publish information regarding this issue or provide notice to customers.


This issue can be triggered by visiting any of the login …

actor attack browser citrix citrix sharefile code context credentials cross-site issue login login credentials malicious page reflected xss scripting security sharefile steal tokens victim xss

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC