S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-27931 Scanner

CVE-2021-27931 scanner - XML External Entity (XXE) vulnerability in LumisXP (aka Lumis Experience Platform)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-27931
9.1
CVSS

LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading local server files or denial of service.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The LumisXP (aka Lumis Experience Platform) is a content management system (CMS) that is widely used by businesses to create and manage their digital assets. With its user-friendly interface and powerful features, the LumisXP allows users to easily build and maintain their websites, intranets, and extranets. The platform integrates with a wide range of third-party tools and services, and provides built-in analytics and personalization capabilities, making it a popular choice among marketing and IT teams alike.

Recently, a vulnerability named CVE-2021-27931 was detected in the LumisXP platform before version 10.0.0. This vulnerability allows unauthenticated blind XML external entity (XXE) attacks via an API request to PageControllerXml.jsp. An attacker can send a request with a crafted XXE payload, which can lead to the reading of local server files or denial of service. The vulnerability affects all versions of the LumisXP platform before version 10.0.0.

If this vulnerability is exploited, it can result in serious consequences for a business. For instance, sensitive information stored on the server could be accessed, such as customer data, financial records, and intellectual property. A successful attack can also cause the LumisXP platform to crash, causing downtime and disruption to business operations. Additionally, the reputation of the business can be at risk, as customers may lose trust in the organization's ability to protect their data.

At s4e.io, we provide pro features that can help businesses quickly and easily learn about vulnerabilities in their digital assets. Our platform offers comprehensive vulnerability scanning and reporting, as well as remediation recommendations to help organizations stay protected against cyber threats. With our advanced security tools and expert support, businesses can rest assured that their digital assets are secure from attackers.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that can be taken, including:

  • Updating to the latest version of the LumisXP platform (version 10.0.0 or later)
  • Implementing web application firewalls to filter out malicious traffic
  • Disabling XML external entity (XXE) processing in the platform's configuration
  • Limiting access to the PageControllerXml.jsp API to trusted IP addresses only
  • Performing regular security assessments and penetration testing to identify vulnerabilities

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-27931 scanner - XML External Entity (XXE) vulnerability in LumisXP (aka Lumis Experience Platform) S4E