Impact
A flaw in Lutece Core’s XSL export management module (up to version 7.1.7) allows authenticated administrators to inject malicious XSL stylesheets that bypass secure processing restrictions and invoke arbitrary Java extension functions. When an manipulated stylesheet is processed during a user export operation, the server executes the embedded Java code, giving the attacker full control of the underlying host. This results in remote code execution on the server with the privileges of the Lutece administrative account.
Affected Systems
Lutece Core versions through 7.1.7 are affected. The vendor has issued a patch for version 7.1.9 that addresses the missing secure processing mode. Only users with administrator privileges can perform the upload and execute the transformation, making the vulnerability limited to accounts that have local administrative access.
Risk and Exploitability
The CVSS score of 9.4 classifies the vulnerability as critical, and the lack of an EPSS score indicates that exploitation frequency is not quantified, but the high severity and reliance on administrator privileges still pose a significant risk. Because attackers need authenticated administrator access, the attack vector is internal‑or‑authenticated. However, once compromised, the attacker can cause arbitrary code execution on the host, with potential full compromise of the system. The vulnerability is not listed in CISA KEV, but the impact warrants prompt remediation.
OpenCVE Enrichment