In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Link | Tags |
---|---|
https://docs.citrix.com/en-us/xenmobile/server/document-history.html | vendor advisory |
https://gist.github.com/tree-chtsec/766f81e22ae383987d75eedb3b23b709 | third party advisory |
https://support.citrix.com/article/CTX370551 | vendor advisory |
https://www.chtsecurity.com/news/09be10ae-b50e-46c9-8ce7-2e995fd988fe |