7.5
CVE-2019-13608
- EPSS 29.4%
- Published 29.08.2019 19:15:13
- Last modified 14.03.2025 20:39:08
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
Data is provided by the National Vulnerability Database (NVD)
Citrix ≫ Storefront Server Version < 1903
Citrix ≫ Storefront Server Version < 3.12.4000
Citrix ≫ Storefront Server Version < 3.0.8000
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability
VulnerabilityCitrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.
DescriptionApply updates per vendor instructions.
Required actionsType | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 29.4% | 0.964 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.