Record summary

CVE-2021-27931 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.

Description

LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading local server files or denial of service.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 22, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALLumisXP <10.0.0 - Blind XML External Entity AttackCVSS 9.1

LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XML external entity (XXE) attacks via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading local server files or denial of service.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information, server compromise, or further attacks on internal systems.

Remediation

Upgrade LumisXP to version 10.0.0 or above to mitigate the vulnerability.

WeaknessesCWE-611
Authorsalph4byt3
Template tagscve2021cvelumisxxeoastblindvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CPE: cpe:2.3:a:lumis:lumis_experience_platform:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2