Логотип exploitDog
bind:CVE-2021-27931
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-27931

Количество 2

Количество 2

nvd логотип

CVE-2021-27931

почти 5 лет назад

LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading local server files or denial of service.

CVSS3: 9.1
EPSS: Критический
github логотип

GHSA-2rf2-p79x-79wj

больше 3 лет назад

LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading local server files or denial of service.

EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-27931

LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading local server files or denial of service.

CVSS3: 9.1
91%
Критический
почти 5 лет назад
github логотип
GHSA-2rf2-p79x-79wj

LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading local server files or denial of service.

91%
Критический
больше 3 лет назад

Уязвимостей на страницу