LumisXP (aka Lumis Experience Platform) prior to 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading local server files or denial of service.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
lumis lumis experience platform |