SQL Injection Vulnerability in Citrix XenMobile Server
CVE-2020-8211
9.8CRITICAL
Summary
Improper input validation in various versions of Citrix XenMobile Server allows attackers to exploit SQL Injection vulnerabilities, potentially leading to unauthorized access to sensitive information. This affects multiple releases, including 10.12 before RP3, 10.11 before RP6, and earlier versions. It is crucial for Citrix users to apply the necessary patches to mitigate the risk associated with this vulnerability.
Affected Version(s)
Citrix XenMobile Server Citrix XenMobile Server 10.12 RP3, Citrix XenMobile Server 10.11 RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved