PT-2023-25102 · Liferay · Liferay Dxp+1

Henrik Bayer

+1

·

Published

2023-06-15

·

Updated

2023-06-22

·

CVE-2023-35030

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Liferay Portal versions 7.4.3.70 through 7.4.3.76 Liferay DXP 7.4 update 70 through 76
Description A cross-site request forgery (CSRF) issue in the Layout module's SEO configuration allows remote attackers to execute arbitrary code in the scripting console via the com liferay layout admin web portlet GroupPagesPortlet backURL parameter.
Recommendations For Liferay Portal versions 7.4.3.70 through 7.4.3.76, consider disabling the SEO configuration in the Layout module until a patch is available. For Liferay DXP 7.4 update 70 through 76, restrict access to the scripting console to minimize the risk of exploitation. Avoid using the com liferay layout admin web portlet GroupPagesPortlet backURL parameter in the affected API endpoint until the issue is resolved.

Fix

RCE

CSRF

Weakness Enumeration

Related Identifiers

CVE-2023-35030
GHSA-P2FC-XXR8-FW3P

Affected Products

Liferay Dxp
Liferay Portal