Vulnerabilities > Liferay > Digital Experience Platform

DATE CVE VULNERABILITY TITLE RISK
2020-09-22 CVE-2020-15839 Unrestricted Upload of File with Dangerous Type vulnerability in Liferay Portal
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.
network
low complexity
liferay CWE-434
6.5