8.8

CVE-2024-26271

Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update 32 through update 36 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the _com_liferay_my_account_web_portlet_MyAccountPortlet_backURL parameter.

Data is provided by the National Vulnerability Database (NVD)
LiferayDigital Experience Platform Version >= 2023.q3.1 < 2023.q3.6
LiferayDigital Experience Platform Version >= 2023.q4.0 < 2023.q4.3
LiferayDigital Experience Platform Version7.3 Updateupdate32
LiferayDigital Experience Platform Version7.3 Updateupdate33
LiferayDigital Experience Platform Version7.3 Updateupdate34
LiferayDigital Experience Platform Version7.3 Updateupdate35
LiferayDigital Experience Platform Version7.4 Updateupdate75
LiferayDigital Experience Platform Version7.4 Updateupdate76
LiferayDigital Experience Platform Version7.4 Updateupdate77
LiferayDigital Experience Platform Version7.4 Updateupdate78
LiferayDigital Experience Platform Version7.4 Updateupdate79
LiferayDigital Experience Platform Version7.4 Updateupdate80
LiferayDigital Experience Platform Version7.4 Updateupdate81
LiferayDigital Experience Platform Version7.4 Updateupdate82
LiferayDigital Experience Platform Version7.4 Updateupdate83
LiferayDigital Experience Platform Version7.4 Updateupdate84
LiferayDigital Experience Platform Version7.4 Updateupdate85
LiferayDigital Experience Platform Version7.4 Updateupdate86
LiferayDigital Experience Platform Version7.4 Updateupdate87
LiferayDigital Experience Platform Version7.4 Updateupdate88
LiferayDigital Experience Platform Version7.4 Updateupdate89
LiferayDigital Experience Platform Version7.4 Updateupdate90
LiferayDigital Experience Platform Version7.4 Updateupdate91
LiferayDigital Experience Platform Version7.4 Updateupdate92
LiferayLiferay Portal Version >= 7.4.3.75 < 7.4.3.112
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.12% 0.321
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
security@liferay.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.