All CVEs — page 44 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This vulnerability allows unauthenticated attackers to execute arbitrary commands due to improper input validation in Citrix NetScaler ADC and Gateway versions prior to 14.1-73.37 and 13.1-64.23, respectively.
The flaw allows attackers to obtain an administrator's token by registering a shop customer account with an administrator's email, granting full administrative access. This is due to the lack of firewall identification in JWT tokens issued by separate Admin and Shop API endpoints.