CVE-2021-29043
- EPSS 0.2%
- Published 17.05.2021 11:15:07
- Last modified 13.05.2025 18:17:51
The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy password, which allows attackers t...
CVE-2021-29044
- EPSS 0.26%
- Published 17.05.2021 11:15:07
- Last modified 13.05.2025 18:17:51
Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pac...
CVE-2021-29045
- EPSS 0.28%
- Published 17.05.2021 11:15:07
- Last modified 21.11.2024 06:00:35
Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com...
CVE-2021-29046
- EPSS 0.26%
- Published 17.05.2021 11:15:07
- Last modified 21.11.2024 06:00:35
Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset_cate...
CVE-2021-29053
- EPSS 0.38%
- Published 17.05.2021 11:15:07
- Last modified 21.11.2024 06:00:36
Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter to (1) CommerceChannelRelFinder.countByC_C, or (2) ...
CVE-2021-29040
- EPSS 0.22%
- Published 16.05.2021 16:15:07
- Last modified 13.05.2025 18:17:51
The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote attackers to use the contents of error...
CVE-2021-29047
- EPSS 0.21%
- Published 16.05.2021 16:15:07
- Last modified 21.11.2024 06:00:35
The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCHA challenge b...
CVE-2021-29039
- EPSS 0.26%
- Published 16.05.2021 15:15:07
- Last modified 21.11.2024 06:00:34
Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inject arbitrary web script or HTML via the site name.
CVE-2020-25476
- EPSS 0.45%
- Published 07.01.2021 17:15:12
- Last modified 21.11.2024 05:18:02
Liferay CMS Portal version 7.1.3 and 7.2.1 have a blind persistent cross-site scripting (XSS) vulnerability in the user name parameter to Calendar. An attacker can insert the malicious payload on the username, lastname or surname fields of its own pr...
CVE-2020-15840
- EPSS 0.25%
- Published 24.09.2020 15:15:14
- Last modified 13.05.2025 18:17:51
In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.