Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.
2020-09-18T21:15:12.827
2024-11-21T05:38:29.337
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | citrix | storefront_server | < 2006 | Yes |
Application | citrix | storefront_server | < 3.0.8001 | Yes |
Application | citrix | storefront_server | < 3.12.5001 | Yes |
Application | citrix | storefront_server | < 1912.0.1000 | Yes |