PT-2023-25102 · Liferay · Liferay Dxp+1
Henrik Bayer
+1
·
Published
2023-06-15
·
Updated
2023-06-22
·
CVE-2023-35030
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Liferay Portal versions 7.4.3.70 through 7.4.3.76
Liferay DXP 7.4 update 70 through 76
Description
A cross-site request forgery (CSRF) issue in the Layout module's SEO configuration allows remote attackers to execute arbitrary code in the scripting console via the
com liferay layout admin web portlet GroupPagesPortlet backURL parameter.Recommendations
For Liferay Portal versions 7.4.3.70 through 7.4.3.76, consider disabling the SEO configuration in the Layout module until a patch is available.
For Liferay DXP 7.4 update 70 through 76, restrict access to the scripting console to minimize the risk of exploitation.
Avoid using the
com liferay layout admin web portlet GroupPagesPortlet backURL parameter in the affected API endpoint until the issue is resolved.Fix
RCE
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Liferay Dxp
Liferay Portal