Lucene search

K
cveHackeroneCVE-2020-8208
HistoryAug 17, 2020 - 4:15 p.m.

CVE-2020-8208

2020-08-1716:15:13
CWE-79
hackerone
web.nvd.nist.gov
35
cve-2020-8208
citrix
xenmobile
server
input validation
xss
cross-site scripting
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

33.8%

Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.11 before RP6 and Citrix XenMobile Server before 10.9 RP5 allows Cross-Site Scripting (XSS).

Affected configurations

Nvd
Node
citrixxenmobile_serverRange10.8.0
OR
citrixxenmobile_serverMatch10.9.0-
OR
citrixxenmobile_serverMatch10.9.0rolling_patch1
OR
citrixxenmobile_serverMatch10.9.0rolling_patch2
OR
citrixxenmobile_serverMatch10.9.0rolling_patch3
OR
citrixxenmobile_serverMatch10.9.0rolling_patch4
OR
citrixxenmobile_serverMatch10.10.0-
OR
citrixxenmobile_serverMatch10.10.0rolling_patch1
OR
citrixxenmobile_serverMatch10.10.0rolling_patch2
OR
citrixxenmobile_serverMatch10.10.0rolling_patch3
OR
citrixxenmobile_serverMatch10.10.0rolling_patch4
OR
citrixxenmobile_serverMatch10.10.0rolling_patch5
OR
citrixxenmobile_serverMatch10.11.0-
OR
citrixxenmobile_serverMatch10.11.0rolling_patch1
OR
citrixxenmobile_serverMatch10.11.0rolling_patch2
OR
citrixxenmobile_serverMatch10.11.0rolling_patch3
OR
citrixxenmobile_serverMatch10.12.0-
OR
citrixxenmobile_serverMatch10.12.0rolling_patch1
VendorProductVersionCPE
citrixxenmobile_server*cpe:2.3:a:citrix:xenmobile_server:*:*:*:*:*:*:*:*
citrixxenmobile_server10.9.0cpe:2.3:a:citrix:xenmobile_server:10.9.0:-:*:*:*:*:*:*
citrixxenmobile_server10.9.0cpe:2.3:a:citrix:xenmobile_server:10.9.0:rolling_patch1:*:*:*:*:*:*
citrixxenmobile_server10.9.0cpe:2.3:a:citrix:xenmobile_server:10.9.0:rolling_patch2:*:*:*:*:*:*
citrixxenmobile_server10.9.0cpe:2.3:a:citrix:xenmobile_server:10.9.0:rolling_patch3:*:*:*:*:*:*
citrixxenmobile_server10.9.0cpe:2.3:a:citrix:xenmobile_server:10.9.0:rolling_patch4:*:*:*:*:*:*
citrixxenmobile_server10.10.0cpe:2.3:a:citrix:xenmobile_server:10.10.0:-:*:*:*:*:*:*
citrixxenmobile_server10.10.0cpe:2.3:a:citrix:xenmobile_server:10.10.0:rolling_patch1:*:*:*:*:*:*
citrixxenmobile_server10.10.0cpe:2.3:a:citrix:xenmobile_server:10.10.0:rolling_patch2:*:*:*:*:*:*
citrixxenmobile_server10.10.0cpe:2.3:a:citrix:xenmobile_server:10.10.0:rolling_patch3:*:*:*:*:*:*
Rows per page:
1-10 of 181

CNA Affected

[
  {
    "product": "Citrix XenMobile Server",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Citrix XenMobile Server 10.12 RP1, Citrix XenMobile Server 10.11 RP4, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

33.8%