vendor:
StoreFront Server
by:
Vahagn Vardanya
8.8
CVSS
HIGH
XML External Entity Injection
611
CWE
Product Name: StoreFront Server
Affected Version From: Citrix StoreFront Server earlier than 1903, Citrix StoreFront Server 7.15 LTSR earlier than CU4 (3.12.4000), Citrix StoreFront Server 7.6 LTSR earlier than CU8 (3.0.8000)
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: a:citrix:storefront_server
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2019
Citrix StoreFront Server 7.15 – XML External Entity Injection
A vulnerability in Citrix StoreFront Server 7.15 allows an attacker to inject malicious XML code into the application, which can be used to perform an XML External Entity (XXE) attack. This attack can be used to gain access to sensitive information stored on the server, such as passwords, configuration files, and other sensitive data. The vulnerability affects Citrix StoreFront Server versions earlier than 1903, Citrix StoreFront Server 7.15 LTSR earlier than CU4 (3.12.4000), and Citrix StoreFront Server 7.6 LTSR earlier than CU8 (3.0.8000).
Mitigation:
The vendor has released a patch to address this vulnerability. Users should upgrade to the latest version of Citrix StoreFront Server.