Liferay

Dxp

187 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 17.05.2021 11:15:07
  • Zuletzt bearbeitet 13.05.2025 18:17:51

The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pack 1 does not obfuscate the S3 store's proxy password, which allows attackers t...

  • EPSS 0.26%
  • Veröffentlicht 17.05.2021 11:15:07
  • Zuletzt bearbeitet 13.05.2025 18:17:51

Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 21, 7.2 before fix pack 10 and 7.3 before fix pac...

  • EPSS 0.28%
  • Veröffentlicht 17.05.2021 11:15:07
  • Zuletzt bearbeitet 21.11.2024 06:00:35

Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.2 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 allows remote attackers to inject arbitrary web script or HTML via the _com...

  • EPSS 0.26%
  • Veröffentlicht 17.05.2021 11:15:07
  • Zuletzt bearbeitet 21.11.2024 06:00:35

Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1, allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_asset_cate...

  • EPSS 0.46%
  • Veröffentlicht 17.05.2021 11:15:07
  • Zuletzt bearbeitet 21.11.2024 06:00:36

Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter to (1) CommerceChannelRelFinder.countByC_C, or (2) ...

  • EPSS 0.52%
  • Veröffentlicht 16.05.2021 16:15:07
  • Zuletzt bearbeitet 21.11.2024 06:00:34

Denial-of-service (DoS) vulnerability in the Multi-Factor Authentication module in Liferay DXP 7.3 before fix pack 1 allows remote authenticated attackers to prevent any user from authenticating by (1) enabling Time-based One-time password (TOTP) on ...

  • EPSS 0.21%
  • Veröffentlicht 16.05.2021 16:15:07
  • Zuletzt bearbeitet 21.11.2024 06:00:35

The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCHA challenge b...