Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nfuse | Citrix | * | 1.6 (including) |
Nfuse | Citrix | 1.51 (including) | 1.51 (including) |