CVE-2020-8209
HIGH EXPLOITED IN THE WILD NUCLEICitrix XenMobile <10.12 - Info Disclosure
Title source: llmDescription
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.
Exploits (2)
github
34 stars
by DarkFunct · cpoc
https://github.com/DarkFunct/CVE_Exploits/tree/main/CVE-2020-8209
Nuclei Templates (1)
Citrix XenMobile Server - Local File Inclusion
HIGHby dwisiswant0
Scores
CVSS v3
7.5
EPSS
0.9301
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
VulnCheck KEV
2023-11-14
InTheWild.io
2021-01-20
CWE
CWE-22
Status
published
Products (5)
citrix/xenmobile_server
10.9.0 (5 CPE variants)
citrix/xenmobile_server
10.10.0 (6 CPE variants)
citrix/xenmobile_server
10.11.0 (4 CPE variants)
citrix/xenmobile_server
10.12.0 (2 CPE variants)
citrix/xenmobile_server
< 10.8.0
Published
Aug 17, 2020
Tracked Since
Feb 18, 2026