Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-27931 PoC — LumisXP 代码问题漏洞

Source
Associated Vulnerability
Title:LumisXP 代码问题漏洞 (CVE-2021-27931)
Description:LumisXP aka Lumis Experience Platform是葡萄牙 (LumisXP)公司的一个应用软件。提供了一个管理客户的平台。 LumisXP before 10.0.0 存在安全漏洞,该漏洞允许通过对PageControllerXml.jsp的API请求进行未经身份验证的盲XXE。
Description
LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XML external entity (XXE) attacks via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading local server files or denial of service.
File Snapshot

id: CVE-2021-27931 info: name: LumisXP <10.0.0 - Blind XML External Entity Attack author: alph4 ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.