Skip to content

Known CVE

LumisXP <10.0.0 - Blind XML External Entity Attack

LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XML external entity (XXE) attacks via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading local server files or denial of service.

CVE-2021-27931

Critical2021CVSS 9.1CWE-611

cve2021 · lumis · xxe · oast · blind · vkev · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website