imPC@ndo IT

Tracker / CVE-2020-8200

CVE-2020-8200

Medium 6.5

Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.

Affected products and versions

citrix storefront_server · … → 2006
citrix storefront_server · 1912 → 1912.0.1000
citrix storefront_server · 3.0 → 3.0.8001
citrix storefront_server · 3.12 → 3.12.5001

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References