QID 376440
Date Published: 2022-03-02
QID 376440: Citrix StoreFront Server Extensible Markup Language (XML) External Entity (XXE) Vulnerability
Citrix StoreFront is an enterprise app store for users that aggregates and presents virtual app and desktop resources from on-premises and hybrid deployments delivering a near-native user experience across Citrix Workspace app (formerly Citrix Receiver) on any platform.
An XML External Entity (XXE) processing vulnerability has been identified in Citrix StoreFront Server that could allow an unauthenticated attacker to retrieve potentially sensitive information from the server.
Affected Versions:
Citrix StoreFront Server earlier than 1903
QID Detection Logic (Authenticated):
This QID checks for Citrix Storefront registry key and checks the presence of CitrixStoreFrontConsole.msc file.
Note: The following versions of Citrix StoreFront server are also affected but are not checked with this QID due to the absence of vulnerable target in our labs
Citrix StoreFront Server 7.15 LTSR earlier than CU4 (3.12.4000)
Citrix StoreFront Server 7.6 LTSR earlier than CU8 (3.0.8000)
Successful exploitation of the vulnerability may allow an unauthenticated attacker to retrieve potentially sensitive information from the server.
- CTX251988 -
support.citrix.com/article/CTX251988
CVEs related to QID 376440
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CTX251988 |
|