8.8
CVE-2021-29050
- EPSS 0.3%
- Veröffentlicht 20.02.2024 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:00:35
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-Site Request Forgery (CSRF) vulnerability in the terms of use page in Liferay Portal before 7.3.6, and Liferay DXP 7.3 before service pack 1, 7.2 before fix pack 11 allows remote attackers to accept the site's terms of use via social engineering and enticing the user to visit a malicious page.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellerliferay
≫
Produkt
dxp
Default Statusunknown
Version <
service pack 1, 7.2
Version
7.3
Status
affected
Version <
fix pack 11
Version
7.3
Status
affected
Herstellerliferay
≫
Produkt
portal
Default Statusunknown
Version <
7.3.6
Version
0
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.532 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.