PT-2023-25102 · Liferay · Liferay Dxp+1
Henrik Bayer
+1
·
Publicado
2023-06-15
·
Atualizado
2023-06-22
·
CVE-2023-35030
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Liferay Portal versions 7.4.3.70 through 7.4.3.76
Liferay DXP 7.4 update 70 through 76
Description
A cross-site request forgery (CSRF) issue in the Layout module's SEO configuration allows remote attackers to execute arbitrary code in the scripting console via the
com liferay layout admin web portlet GroupPagesPortlet backURL parameter.Recommendations
For Liferay Portal versions 7.4.3.70 through 7.4.3.76, consider disabling the SEO configuration in the Layout module until a patch is available.
For Liferay DXP 7.4 update 70 through 76, restrict access to the scripting console to minimize the risk of exploitation.
Avoid using the
com liferay layout admin web portlet GroupPagesPortlet backURL parameter in the affected API endpoint until the issue is resolved.Correção
RCE
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Liferay Dxp
Liferay Portal