.. / CVE-2020-8982

Exploit for Citrix ShareFile StorageZones <=5.10.x - Arbitrary File Read (CVE-2020-8982)

Description:

Citrix ShareFile StorageZones (aka storage zones) Controller versions through at least 5.10.x are susceptible to an unauthenticated arbitrary file read vulnerability.

Nuclei Template

View the template here CVE-2020-8982.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-8982.yaml
Copy

References:

https://www.linkedin.com/posts/jonas-hansen-2a2606b_citrix-sharefile-storage-zones-controller-activity-6663432907455025152-8_w6/
https://github.com/0xT11/CVE-POC
https://drive.google.com/file/d/1Izd5MF_HHuq8YSwAyJLBErWL_nbe6f9v/view
https://nvd.nist.gov/vuln/detail/CVE-2020-8982
https://support.citrix.com/article/CTX269106