Vulnerabilities > Liferay > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-08-04 | CVE-2021-33338 | Cross-Site Request Forgery (CSRF) vulnerability in Liferay DXP and Liferay Portal The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 6, exposes the CSRF token in URLs, which allows man-in-the-middle attackers to obtain the token and conduct Cross-Site Request Forgery (CSRF) attacks via the p_auth parameter. | 7.5 |
2021-08-03 | CVE-2021-33335 | Incorrect Authorization vulnerability in Liferay DXP and Liferay Portal Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows remote authenticated users with permission to update/edit users to take over a company administrator user account by editing the company administrator user. | 7.2 |
2021-08-03 | CVE-2021-33321 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Liferay DXP 7.0 Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attackers to enumerate user email address via the forgot password functionality. | 7.5 |
2021-08-03 | CVE-2021-33322 | Insufficient Session Expiration vulnerability in Liferay DXP 7.0 In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 18, and 7.2 before fix pack 5, password reset tokens are not invalidated after a user changes their password, which allows remote attackers to change the user’s password via the old password reset token. | 7.5 |
2021-08-03 | CVE-2021-33323 | Cleartext Storage of Sensitive Information vulnerability in Liferay DXP and Liferay Portal The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 7, autosaves form values for unauthenticated users, which allows remote attackers to view the autosaved values by viewing the form as an unauthenticated user. | 7.5 |
2021-05-17 | CVE-2021-29053 | SQL Injection vulnerability in Liferay DXP and Liferay Portal Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter to (1) CommerceChannelRelFinder.countByC_C, or (2) CommerceChannelRelFinder.findByC_C. | 8.8 |
2021-05-16 | CVE-2021-29047 | Improper Authentication vulnerability in Liferay DXP and Liferay Portal The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCHA challenge by reusing the same CAPTCHA answer. | 7.5 |
2020-09-01 | CVE-2020-24554 | Open Redirect vulnerability in Liferay Portal The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote attackers to perform a denial of service attack by making repeated requests for pages that do not exist. | 7.5 |
2020-07-20 | CVE-2020-15842 | Deserialization of Untrusted Data vulnerability in Liferay Portal Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle attackers to execute arbitrary code via crafted serialized payloads, because of insecure deserialization. | 8.1 |
2020-07-20 | CVE-2020-15841 | Unspecified vulnerability in Liferay Portal Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 89, 7.1 before fix pack 17, and 7.2 before fix pack 4, does not safely test a connection to a LDAP server, which allows remote attackers to obtain the LDAP server's password via the Test LDAP Connection feature. | 8.8 |