PT-2023-25102 · Liferay · Liferay Dxp+1

Henrik Bayer

+1

·

Publicado

2023-06-15

·

Atualizado

2023-06-22

·

CVE-2023-35030

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.4.3.70 through 7.4.3.76 Liferay DXP 7.4 update 70 through 76
Description A cross-site request forgery (CSRF) issue in the Layout module's SEO configuration allows remote attackers to execute arbitrary code in the scripting console via the com liferay layout admin web portlet GroupPagesPortlet backURL parameter.
Recommendations For Liferay Portal versions 7.4.3.70 through 7.4.3.76, consider disabling the SEO configuration in the Layout module until a patch is available. For Liferay DXP 7.4 update 70 through 76, restrict access to the scripting console to minimize the risk of exploitation. Avoid using the com liferay layout admin web portlet GroupPagesPortlet backURL parameter in the affected API endpoint until the issue is resolved.

Correção

RCE

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-35030
GHSA-P2FC-XXR8-FW3P

Produtos afetados

Liferay Dxp
Liferay Portal