8.8

CVE-2023-35030

Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to execute arbitrary code in the scripting console via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Liferay ≫ Dxp Version 7.4 Update update_70
Liferay ≫ Dxp Version 7.4 Update update_71
Liferay ≫ Dxp Version 7.4 Update update_72
Liferay ≫ Dxp Version 7.4 Update update_73
Liferay ≫ Dxp Version 7.4 Update update_74
Liferay ≫ Dxp Version 7.4 Update update_75
Liferay ≫ Dxp Version 7.4 Update update_76
Liferay ≫ Liferay Portal Version >= 7.4.3.70 < 7.4.3.77
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.32
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
security@liferay.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-35030
Patch
Vendor Advisory