Vulnerabilities > Liferay > DXP > High

DATE CVE VULNERABILITY TITLE RISK
2024-02-08 CVE-2024-25148 Unspecified vulnerability in Liferay DXP and Liferay Portal
In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions the `doAsUserId` URL parameter may get leaked when creating linked content using the WYSIWYG editor and while impersonating a user.
network
low complexity
liferay
8.1
2023-06-15 CVE-2023-35030 Cross-Site Request Forgery (CSRF) vulnerability in Liferay DXP and Liferay Portal
Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to execute arbitrary code in the scripting console via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
network
low complexity
liferay CWE-352
8.8
2022-11-15 CVE-2022-42121 SQL Injection vulnerability in Liferay DXP and Liferay Portal
A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field.
network
low complexity
liferay CWE-89
8.8
2021-08-04 CVE-2021-33338 Cross-Site Request Forgery (CSRF) vulnerability in Liferay DXP and Liferay Portal
The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 6, exposes the CSRF token in URLs, which allows man-in-the-middle attackers to obtain the token and conduct Cross-Site Request Forgery (CSRF) attacks via the p_auth parameter.
network
high complexity
liferay CWE-352
7.5
2021-08-03 CVE-2021-33335 Incorrect Authorization vulnerability in Liferay DXP and Liferay Portal
Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows remote authenticated users with permission to update/edit users to take over a company administrator user account by editing the company administrator user.
network
low complexity
liferay CWE-863
7.2
2021-08-03 CVE-2021-33321 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Liferay DXP 7.0
Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality.
network
low complexity
liferay CWE-640
7.5
2021-08-03 CVE-2021-33322 Insufficient Session Expiration vulnerability in Liferay DXP 7.0
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 18, and 7.2 before fix pack 5, password reset tokens are not invalidated after a user changes their password, which allows remote attackers to change the user’s password via the old password reset token.
network
low complexity
liferay CWE-613
7.5
2021-08-03 CVE-2021-33323 Cleartext Storage of Sensitive Information vulnerability in Liferay DXP and Liferay Portal
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves form values for unauthenticated users, which allows remote attackers to view the autosaved values by viewing the form as an unauthenticated user.
network
low complexity
liferay CWE-312
7.5
2021-05-17 CVE-2021-29053 SQL Injection vulnerability in Liferay DXP and Liferay Portal
Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter to (1) CommerceChannelRelFinder.countByC_C, or (2) CommerceChannelRelFinder.findByC_C.
network
low complexity
liferay CWE-89
8.8
2021-05-16 CVE-2021-29047 Improper Authentication vulnerability in Liferay DXP and Liferay Portal
The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCHA challenge by reusing the same CAPTCHA answer.
network
low complexity
liferay CWE-287
7.5