CVE-2019-7217

HIGH

Citrix ShareFile <19.12 - Info Disclosure

Title source: llm
STIX 2.1

Description

Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication is required.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
http://www.sk-it.com/en/cve.html

Scores

CVSS v3 7.5
EPSS 0.0045
EPSS Percentile 63.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-203
Status published
Products (1)
citrix/sharefile < 19.12
Published May 13, 2019
Tracked Since Feb 18, 2026