VulnerabilityModified
CVE-2021-27931
LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp.
CRITICAL 9.1EPSS 18.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.1%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading local server files or denial of service.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- EPSS
- 18.13% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- lumis/lumis experience platform
- Source
- cve@mitre.org
References
- https://github.com/sl4cky/LumisXP-XXE---POC/blob/main/poc.txtExploit, Third Party Advisory
- https://github.com/sl4cky/LumisXP-XXE---POC/blob/main/poc.txtExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.