Executive brief
Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability due to improper restriction of XML external entity references. An unauthenticated attacker can exploit this to retrieve sensitive information from the server.
Affected products
- Citrix StoreFront Server before 1903
- Citrix StoreFront Server 7.15 LTSR before CU4 (3.12.4000)
- Citrix StoreFront Server 7.6 LTSR before CU8 (3.0.8000)
Timeline
- 2019-08-29: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Confirmed exploited in the wild per CISA KEV catalog entry