7.5

CVE-2021-33338

The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 6, exposes the CSRF token in URLs, which allows man-in-the-middle attackers to obtain the token and conduct Cross-Site Request Forgery (CSRF) attacks via the p_auth parameter.

Data is provided by the National Vulnerability Database (NVD)
LiferayDigital Experience Platform Version7.1 Update-
LiferayDigital Experience Platform Version7.1 Updatefix_pack_1
LiferayDigital Experience Platform Version7.1 Updatefix_pack_10
LiferayDigital Experience Platform Version7.1 Updatefix_pack_11
LiferayDigital Experience Platform Version7.1 Updatefix_pack_12
LiferayDigital Experience Platform Version7.1 Updatefix_pack_13
LiferayDigital Experience Platform Version7.1 Updatefix_pack_14
LiferayDigital Experience Platform Version7.1 Updatefix_pack_15
LiferayDigital Experience Platform Version7.1 Updatefix_pack_16
LiferayDigital Experience Platform Version7.1 Updatefix_pack_17
LiferayDigital Experience Platform Version7.1 Updatefix_pack_18
LiferayDigital Experience Platform Version7.1 Updatefix_pack_2
LiferayDigital Experience Platform Version7.1 Updatefix_pack_3
LiferayDigital Experience Platform Version7.1 Updatefix_pack_4
LiferayDigital Experience Platform Version7.1 Updatefix_pack_5
LiferayDigital Experience Platform Version7.1 Updatefix_pack_6
LiferayDigital Experience Platform Version7.1 Updatefix_pack_7
LiferayDigital Experience Platform Version7.1 Updatefix_pack_8
LiferayDigital Experience Platform Version7.1 Updatefix_pack_9
LiferayDigital Experience Platform Version7.2 Update-
LiferayDigital Experience Platform Version7.2 Updatefix_pack_1
LiferayDigital Experience Platform Version7.2 Updatefix_pack_2
LiferayDigital Experience Platform Version7.2 Updatefix_pack_3
LiferayDigital Experience Platform Version7.2 Updatefix_pack_4
LiferayDigital Experience Platform Version7.2 Updatefix_pack_5
LiferayLiferay Portal Version >= 7.1.0 <= 7.3.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.263
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.