PT-2019-12309 · Liferay · Liferay Portal

Akkus

+1

·

Publicado

2019-04-22

·

Atualizado

2024-08-04

·

CVE-2019-11444

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Liferay Portal CE version 7.1.2 GA3
Description An issue in Liferay Portal CE allows an attacker to execute OS commands using the Groovy script console. This can be achieved via a command.execute() call. The attacker needs valid credentials for an application administrator user account to exploit this issue. The exploitation can be demonstrated by setting "def cmd =" in the ServerAdminPortlet script value to group/control panel/manage.
Recommendations For Liferay Portal CE version 7.1.2 GA3, consider restricting access to the Groovy script console to minimize the risk of exploitation. As a temporary workaround, limit the use of the command.execute() call in the Groovy script console until a more robust solution is available.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11444

Produtos afetados

Liferay Portal