logo

Compromising Citrix ShareFile on-premise via 7 chained vulnerabilities

ID: 72dfcff3-6def-5d1e-ab37-a74088157c6f

STIX ID: report--72dfcff3-6def-5d1e-ab37-a74088157c6f

Feed Name: Fox-IT blog

Threat Score
75/100

Date Published: 2018-04-06

Date Updated: 2026-04-27

...
...

Fox-IT analyzed Citrix ShareFile's on-premise StorageZone controller and documented a chain of eight vulnerabilities—multiple path traversals in ZIP extraction and upload IDs, weak/guessable integrity checks on info/token files, HMAC verification flaws (HTTP parameter pollution), and debug information disclosure—that together allow any account able to upload files to read, modify, and download arbitrary files (including encrypted storage) from vulnerable on-premise StorageZone installations; Citrix deployed mitigations after coordinated disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.