CVE-2018-10649: XSS
Published May 23, 2018
·Updated
There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.
Affected Software
3 affected components
Citrix XenMobile Server=10.7
Citrix XenMobile Server=10.7-rp1
Citrix XenMobile Server=10.7-rp2
Event History
May 23, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10649?
CVE-2018-10649 has a medium severity rating due to its potential for Cross-Site Scripting attacks.
2
How do I fix CVE-2018-10649?
To fix CVE-2018-10649, upgrade Citrix XenMobile Server to version 10.7 RP3 or later.
3
What types of attacks can CVE-2018-10649 facilitate?
CVE-2018-10649 can facilitate Cross-Site Scripting attacks, allowing attackers to inject malicious scripts.
4
Which versions of Citrix XenMobile Server are affected by CVE-2018-10649?
CVE-2018-10649 affects Citrix XenMobile Server versions 10.7 and earlier RP versions, including 10.7 RP1 and 10.7 RP2.
5
Is there a workaround for CVE-2018-10649 if I cannot upgrade?
There are no specified workarounds for CVE-2018-10649; upgrading is the recommended course of action.