vendor:
XenMobile Server
by:
Jonas Lejon
9.8
CVSS
CRITICAL
XML External Entity Injection
611
CWE
Product Name: XenMobile Server
Affected Version From: XenMobile Server 10.8 before RP2 and 10.7 before RP3
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2018-10653
CPE: a:citrix:xenmobile_server:10.8
Platforms Tested: XenMobile
2019
Citrix XenMobile Server 10.8 – XML External Entity Injection
This exploit allows an attacker to inject XML external entities into the Citrix XenMobile Server, potentially leading to disclosure of internal files or denial of service attacks. The vulnerability exists in XenMobile Server 10.8 before RP2 and 10.7 before RP3. By sending a specially crafted XML payload, an attacker can exploit this vulnerability to trigger the XXE vulnerability and perform unauthorized actions.
Mitigation:
Citrix released a patch in May 2018 to address this vulnerability. Users are advised to update to XenMobile Server 10.8 RP2 or 10.7 RP3 or later versions to mitigate this vulnerability.