Junglewise Threat Intelligence

CVE-2019-13608: Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability

CVE-2019-13608 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2021-11-03

Vendors: Citrix.

Executive brief

Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability due to improper restriction of XML external entity references. An unauthenticated attacker can exploit this to retrieve sensitive information from the server.

Affected products

  • Citrix StoreFront Server before 1903
  • Citrix StoreFront Server 7.15 LTSR before CU4 (3.12.4000)
  • Citrix StoreFront Server 7.6 LTSR before CU8 (3.0.8000)

Timeline

  • 2019-08-29: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Confirmed exploited in the wild per CISA KEV catalog entry