Vulnerabilities > CVE-2018-10653 - XXE vulnerability in Citrix Xenmobile Server 10.7/10.8
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
Common Weakness Enumeration (CWE)
Exploit-Db
id | EDB-ID:47951 |
last seen | 2020-01-22 |
modified | 2020-01-22 |
published | 2020-01-22 |
reporter | Exploit-DB |
source | https://www.exploit-db.com/download/47951 |
title | Citrix XenMobile Server 10.8 - XML External Entity Injection |
Packetstorm
data source | https://packetstormsecurity.com/files/download/156037/citrixxms108-xml.txt |
id | PACKETSTORM:156037 |
last seen | 2020-01-23 |
published | 2020-01-22 |
reporter | Jonas Lejon |
source | https://packetstormsecurity.com/files/156037/Citrix-XenMobile-Server-10.8-XML-Injection.html |
title | Citrix XenMobile Server 10.8 XML Injection |