There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
https://support.citrix.com/article/CTX234879
https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-2725
http://packetstormsecurity.com/files/156037/Citrix-XenMobile-Server-10.8-XML-Injection.html