Vulnerabilities > Liferay

DATE CVE VULNERABILITY TITLE RISK
2023-04-16 CVE-2021-33990 Improper Preservation of Permissions vulnerability in Liferay Portal 6.2.5
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists.
network
low complexity
liferay CWE-281
critical
9.8
2022-11-15 CVE-2022-42129 Authorization Bypass Through User-Controlled Key vulnerability in Liferay Digital Experience Platform and Liferay Portal
An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 through 7.4.3.4, and Liferay DXP 7.3 before update 4, and 7.4 GA allows remote authenticated users to view and access form entries via the `formInstanceRecordId` parameter.
network
low complexity
liferay CWE-639
4.3
2022-11-15 CVE-2022-42130 Incorrect Default Permissions vulnerability in Liferay Digital Experience Platform and Liferay Portal
The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 19, 7.3 before update 4, and 7.4 GA does not properly check permission of form entries, which allows remote authenticated users to view and access all form entries.
network
low complexity
liferay CWE-276
4.3
2022-11-15 CVE-2022-42131 Improper Certificate Validation vulnerability in Liferay Digital Experience Platform and Liferay Portal
Certain Liferay products are affected by: Missing SSL Certificate Validation in the Dynamic Data Mapping module's REST data providers.
network
high complexity
liferay CWE-295
4.8
2022-11-15 CVE-2022-42132 Information Exposure vulnerability in Liferay Digital Experience Platform 7.0/7.1/7.2
The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier, 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before update 4, and DXP 7.4 GA includes the LDAP credential in the page URL when paginating through the list of users, which allows man-in-the-middle attackers or attackers with access to the request logs to see the LDAP credential.
network
high complexity
liferay CWE-200
5.9
2022-11-15 CVE-2022-42111 Cross-site Scripting vulnerability in Liferay DXP and Liferay Portal
A Cross-site scripting (XSS) vulnerability in the Sharing module's user notification in Liferay Portal 7.2.1 through 7.4.2, and Liferay DXP 7.2 before fix pack 19, and 7.3 before update 4 allows remote attackers to inject arbitrary web script or HTML by sharing an asset with a crafted payload.
network
low complexity
liferay CWE-79
5.4
2022-11-15 CVE-2022-42118 Cross-site Scripting vulnerability in Liferay Portal
A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 15, and 7.3 before service pack 3 allows remote attackers to inject arbitrary web script or HTML via the `tag` parameter.
network
low complexity
liferay CWE-79
6.1
2022-11-15 CVE-2022-42119 Cross-site Scripting vulnerability in Liferay DXP and Liferay Portal
Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module.
network
low complexity
liferay CWE-79
5.4
2022-11-15 CVE-2022-42120 SQL Injection vulnerability in Liferay DXP and Liferay Portal
A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.
network
low complexity
liferay CWE-89
critical
9.8
2022-11-15 CVE-2022-42121 SQL Injection vulnerability in Liferay DXP and Liferay Portal
A SQL injection vulnerability in the Layout module in Liferay Portal 7.1.3 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 17, 7.3 before service pack 3, and 7.4 GA allows remote authenticated attackers to execute arbitrary SQL commands via a crafted payload injected into a page template's 'Name' field.
network
low complexity
liferay CWE-89
8.8