First published: Thu Aug 29 2019(Updated: )
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix StoreFront | ||
Citrix StoreFront | <1903 | |
Citrix StoreFront | <3.12.4000 | |
Citrix StoreFront | <3.0.8000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13608 has been rated as high severity due to its potential exploitation by unauthenticated attackers.
To fix CVE-2019-13608, upgrade Citrix StoreFront Server to version 1903 or higher, or apply the appropriate cumulative updates for earlier versions.
CVE-2019-13608 allows for XML External Entity (XXE) attacks which can lead to unauthorized data exposure.
CVE-2019-13608 affects Citrix StoreFront Server versions prior to 1903, 7.15 LTSR before CU4, and 7.6 LTSR before CU8.
Yes, CVE-2019-13608 can be exploited remotely by an unauthenticated attacker.