Vulnerabilities > Liferay > Liferay Portal > 4.1.0

DATE CVE VULNERABILITY TITLE RISK
2022-03-03 CVE-2021-38263 Cross-site Scripting vulnerability in Liferay Portal
Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 101, 7.1 before fix pack 20 and 7.2 before fix pack 10 allows remote attackers to inject arbitrary web script or HTML via the output of a script.
network
low complexity
liferay CWE-79
6.1
2021-08-03 CVE-2021-33333 Incorrect Default Permissions vulnerability in Liferay DXP 7.0
The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19 and 7.2 before fix pack 6, does not properly check user permission, which allows remote authenticated users to view and delete workflow submissions via crafted URLs.
network
low complexity
liferay CWE-276
6.3
2021-08-03 CVE-2021-33320 Allocation of Resources Without Limits or Throttling vulnerability in Liferay DXP 7.0
The Flags module in Liferay Portal 7.3.1 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, and 7.2 before fix pack 5, does not limit the rate at which content can be flagged as inappropriate, which allows remote authenticated users to spam the site administrator with emails
network
low complexity
liferay CWE-770
4.3
2021-08-03 CVE-2021-33322 Insufficient Session Expiration vulnerability in Liferay DXP 7.0
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 18, and 7.2 before fix pack 5, password reset tokens are not invalidated after a user changes their password, which allows remote attackers to change the user’s password via the old password reset token.
network
low complexity
liferay CWE-613
7.5
2021-08-03 CVE-2021-33325 Cleartext Storage of Sensitive Information vulnerability in Liferay DXP 7.0
The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19, and 7.2 before fix pack 7, user's clear text passwords are stored in the database if workflow is enabled for user creation, which allows attackers with access to the database to obtain a user's password.
network
low complexity
liferay CWE-312
4.9
2021-08-03 CVE-2021-33326 Cross-site Scripting vulnerability in Liferay DXP 7.0
Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20 and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the title of a modal window.
network
low complexity
liferay CWE-79
6.1
2021-05-16 CVE-2021-29040 Information Exposure Through an Error Message vulnerability in Liferay DXP 7.0
The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote attackers to use the contents of error messages to help launch another, more focused attacks via crafted inputs.
network
low complexity
liferay CWE-209
5.3
2020-09-24 CVE-2020-15840 Unspecified vulnerability in Liferay DXP and Liferay Portal
In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property 'portlet.resource.id.banned.paths.regexp' can be bypassed with doubled encoded URLs.
network
low complexity
liferay
5.3
2020-09-22 CVE-2020-15839 Unrestricted Upload of File with Dangerous Type vulnerability in Liferay Portal
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.
network
low complexity
liferay CWE-434
6.5
2020-09-01 CVE-2020-24554 Open Redirect vulnerability in Liferay Portal
The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote attackers to perform a denial of service attack by making repeated requests for pages that do not exist.
network
low complexity
liferay CWE-601
7.5