PT-2020-5826 · Citrix · Citrix Xenmobile Server

Published

2020-08-12

·

Updated

2020-08-19

·

CVE-2020-8208

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Citrix XenMobile Server versions 10.12 before RP1 Citrix XenMobile Server versions 10.11 before RP4 Citrix XenMobile Server versions 10.11 before RP6 Citrix XenMobile Server versions prior to 10.9 RP5
Description: The issue is related to improper input validation in Citrix XenMobile Server, which may allow a remote attacker to gain unauthorized access to protected information. This can lead to Cross-Site Scripting (XSS) attacks.
Recommendations: For Citrix XenMobile Server version 10.12 before RP1, update to a version that includes RP1 or later to resolve the issue. For Citrix XenMobile Server version 10.11 before RP4, update to a version that includes RP4 or later to resolve the issue. For Citrix XenMobile Server version 10.11 before RP6, update to a version that includes RP6 or later to resolve the issue. For Citrix XenMobile Server versions prior to 10.9 RP5, update to version 10.9 RP5 or later to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01795
CVE-2020-8208

Affected Products

Citrix Xenmobile Server