What is Citrix Content Collaboration?
Citrix Content Collaboration is a security-focused collaboration, content sharing and synchronization service from Citrix for the enterprise.
What is the Attack?
CVE-2023-24489 is a directory traversal vulnerability that affects Citrix Systems ShareFile StorageZones Controller prior to 5.11.24.
The vulnerability is due to improper validation of user input in the ProcessRawPostedFile function. A remote, unauthenticated attacker could exploit this vulnerability by sending crafted requests to the target server. Successful exploitation could allow an attacker to save files to an arbitrary file path under the web root directory, which could lead to the execution of arbitrary code.
The vulnerability has a CVSS score of 9.1 and is rated critical by Citrix.
Why is this Significant?
This is significant because CISA added CVE-2023-24489 to the Known Exploited Vulnerabilities catalog on August 16, 2023, indicating that an attempted or successful exploitation has been observed. Therefore, FortiGuard Labs advises all users of the service to apply the patch as soon as possible.
What is the Vendor Solution?
Citrix released relevant updates in June, 2023.
What FortiGuard Coverage is available?
FortiGuard Labs has an IPS signature “C Citrix.ShareFile.SZC.ProcessRawPostedFile.Directory.Traversal” in place for CVE-2023-24489.
More Stories
lemonldap-ng-2.21.0-1.fc42
FEDORA-2025-aacd0b82cc Packages in this update: lemonldap-ng-2.21.0-1.fc42 Update description: See https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-21-0-is-out/ Read More
lemonldap-ng-2.21.0-1.el9
FEDORA-EPEL-2025-0d5707b1a1 Packages in this update: lemonldap-ng-2.21.0-1.el9 Update description: See https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-21-0-is-out/ Read More
lemonldap-ng-2.21.0-1.fc40
FEDORA-2025-80dfa228e7 Packages in this update: lemonldap-ng-2.21.0-1.fc40 Update description: See https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-21-0-is-out/ Read More
lemonldap-ng-2.21.0-1.el8
FEDORA-EPEL-2025-2ad1cee164 Packages in this update: lemonldap-ng-2.21.0-1.el8 Update description: See https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-21-0-is-out/ Read More
lemonldap-ng-2.21.0-1.fc41
FEDORA-2025-273b88cf62 Packages in this update: lemonldap-ng-2.21.0-1.fc41 Update description: See https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-21-0-is-out/ Read More
USN-7408-4: Linux kernel (HWE) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This...