Cross-Site Request Forgery (CSRF) vulnerability in the terms of use page in Liferay Portal before 7.3.6, and Liferay DXP 7.3 before service pack 1, 7.2 before fix pack 11 allows remote attackers to accept the site's terms of use via social engineering and enticing the user to visit a malicious page.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-15696 | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery in Terms of Use Page |
Github GHSA |
GHSA-mh9r-9pcx-rx55 | Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery in Terms of Use Page |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 24 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Liferay
Liferay dxp Liferay portal |
|
| CPEs | cpe:2.3:a:liferay:dxp:-:*:*:*:*:*:*:* cpe:2.3:a:liferay:portal:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Liferay
Liferay dxp Liferay portal |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-24T15:06:41.135Z
Reserved: 2021-03-22T00:00:00.000Z
Link: CVE-2021-29050
Updated: 2024-08-03T21:55:12.555Z
Status : Awaiting Analysis
Published: 2024-02-20T22:15:08.067
Modified: 2024-11-21T06:00:35.950
Link: CVE-2021-29050
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA