Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-27931

LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading local server files or denial of service.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.866
EPSS Ranking 99.4%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 6.4
Products affected by CVE-2021-27931


Contact Us

Shodan ® - All rights reserved