Show filters
48 Total Results
Displaying 41-48 of 48
Sort by:
Attacker Value
Unknown

CVE-2020-15839

Disclosure Date: September 22, 2020 (last updated February 22, 2025)
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.
Attacker Value
Unknown

CVE-2020-15842

Disclosure Date: July 20, 2020 (last updated February 21, 2025)
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle attackers to execute arbitrary code via crafted serialized payloads, because of insecure deserialization.
Attacker Value
Unknown

CVE-2020-15841

Disclosure Date: July 20, 2020 (last updated November 28, 2024)
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote attackers to obtain the LDAP server's password via the Test LDAP Connection feature.
Attacker Value
Unknown

CVE-2020-13445

Disclosure Date: June 10, 2020 (last updated February 21, 2025)
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensitive objects, which allows remote authenticated users to execute arbitrary code via crafted FreeMarker and Velocity templates.
Attacker Value
Unknown

CVE-2020-13444

Disclosure Date: June 10, 2020 (last updated November 28, 2024)
Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.
Attacker Value
Unknown

CVE-2019-16891

Disclosure Date: October 04, 2019 (last updated November 27, 2024)
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
Attacker Value
Unknown

CVE-2019-6588

Disclosure Date: June 03, 2019 (last updated November 27, 2024)
In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsanitized input into the "url" parameter of the JSP taglib call <liferay-ui:captcha url="<%= url %>" /> or <liferay-captcha:captcha url="<%= url %>" />. Liferay Portal out-of-the-box behavior with no customizations is not vulnerable.
0
Attacker Value
Unknown

CVE-2019-11444

Disclosure Date: April 22, 2019 (last updated November 08, 2023)
An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be executed via a [command].execute() call, as demonstrated by "def cmd =" in the ServerAdminPortlet_script value to group/control_panel/manage. Valid credentials for an application administrator user account are required. NOTE: The developer disputes this as a vulnerability since it is a feature for administrators to run groovy scripts and therefore not a design flaw
0