CVE-2019-13608

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
29/08/2019
Last modified:
14/03/2025

Description

Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:citrix:storefront_server:*:*:*:*:*:*:*:* 1903 (excluding)
cpe:2.3:a:citrix:storefront_server:*:*:*:*:*:*:*:* 3.12.4000 (excluding)
cpe:2.3:a:citrix:storefront_server:*:*:*:*:*:*:*:* 3.0.8000 (excluding)