CVE-2024-33329
HIGHLumisxp 15.0.x-16.1.x - Unauthenticated Authentication Bypass via Hardcoded Credentials
Title source: llmDescription
A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access internal pages and other sensitive information.
References (2)
Core 2
Core References
Various Sources
https://gist.github.com/rodnt/f6b3a2ac875b8f13656063eefbfd9812
Mailing List mailing-list
http://seclists.org/fulldisclosure/2024/Jul/7
Scores
CVSS v3
7.5
EPSS
0.0068
EPSS Percentile
47.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-798
Status
published
Published
Jun 26, 2024
Tracked Since
Feb 18, 2026