CVE-2019-18910: HP Thinpro

Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.

The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with local user privileges.

Affected products

  • HP Thinpro: version 6.2 only; version 6.2.1 only; version 7.0 only; version 7.1 only

Published 2019-11-22. Last modified 2026-06-17.