Compromising Citrix ShareFile on-premise via 7 chained vulnerabilities
ID: 72dfcff3-6def-5d1e-ab37-a74088157c6f
STIX ID: report--72dfcff3-6def-5d1e-ab37-a74088157c6f
Feed Name: Fox-IT blog
Fox-IT analyzed Citrix ShareFile's on-premise StorageZone controller and documented a chain of eight vulnerabilities—multiple path traversals in ZIP extraction and upload IDs, weak/guessable integrity checks on info/token files, HMAC verification flaws (HTTP parameter pollution), and debug information disclosure—that together allow any account able to upload files to read, modify, and download arbitrary files (including encrypted storage) from vulnerable on-premise StorageZone installations; Citrix deployed mitigations after coordinated disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
