Vulnerabilities > Liferay > Liferay Portal > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-24 | CVE-2023-33945 | SQL Injection vulnerability in Liferay Digital Experience Platform and Liferay Portal SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.4.3.17, and Liferay DXP 7.3 before update 6, and 7.4 before update 18 allows attackers to execute arbitrary SQL commands via the name of a database table's primary key index. | 8.1 |
2023-05-24 | CVE-2023-33948 | Missing Authorization vulnerability in Liferay Digital Experience Platform and Liferay Portal The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downloaded from a Form, which allows remote attackers to download any file from Document and Media via a crafted URL. | 7.5 |
2022-11-15 | CVE-2022-42121 | SQL Injection vulnerability in Liferay DXP and Liferay Portal A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field. | 8.8 |
2022-11-15 | CVE-2022-42123 | Path Traversal vulnerability in Liferay Digital Experience Platform and Liferay Portal A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin. | 7.5 |
2022-11-15 | CVE-2022-42124 | Unspecified vulnerability in Liferay Digital Experience Platform and Liferay Portal ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2 fix pack 9 through fix pack 18, 7.3 before update 4, and DXP 7.4 GA allows remote attackers to consume an excessive amount of server resources via a crafted payload injected into the 'name' field of a layout prototype. | 7.5 |
2022-11-15 | CVE-2022-42125 | Path Traversal vulnerability in Liferay Digital Experience Platform and Liferay Portal Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create or overwrite existing files on the filesystem via the deployment of a malicious plugin/module. | 7.5 |
2022-09-22 | CVE-2022-28981 | Path Traversal vulnerability in Liferay Portal 7.4.0/7.4.1/7.4.2 Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to access files outside of com.liferay.headless.discovery.web/META-INF/resources via the `parameter` parameter. | 7.5 |
2022-03-02 | CVE-2021-38266 | Unspecified vulnerability in Liferay Portal The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP, which allows remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exist in LDAP. | 7.5 |
2022-01-28 | CVE-2020-28884 | OS Command Injection vulnerability in Liferay Portal 7.2/7.3.5 Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. | 7.2 |
2022-01-28 | CVE-2020-28885 | OS Command Injection vulnerability in Liferay Portal 7.2/7.3.5 Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. | 7.2 |