Aug. 28, 2023, 6:23 p.m. | Jimi Sebree

Tenable Research Advisories www.tenable.com

Citrix ShareFile Reflected XSS on Login Page

A security-related issue with Citrix ShareFile login pages has been discovered. The issue is a reflected cross-site scripting attack which could allow a malicious actor to steal login credentials, tokens, execute code in the context of a victim's browser, or perform a variety of other malicious actions.


Citrix has elected not to publish information regarding this issue or provide notice to customers.


This issue can be triggered by visiting any of the login …

actor attack browser citrix citrix sharefile code context credentials cross-site issue login login credentials malicious page reflected xss scripting security sharefile steal tokens victim xss

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

SITEC- Systems Security Administrator- Camp HM Smith

@ Peraton | Camp H.M. Smith, HI, United States

Cyberspace Intelligence Analyst

@ Peraton | Fort Meade, MD, United States

General Manager, Cybersecurity, Google Public Sector

@ Google | Virginia, USA; United States

Cyber Security Advisor

@ H&M Group | Stockholm, Sweden

Engineering Team Manager – Security Controls

@ H&M Group | Stockholm, Sweden