Description
Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to execute arbitrary code in the scripting console via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-39067 | Liferay Portal and Liferay DXP Vulnerable to CSRF via the Layout Module |
Github GHSA |
GHSA-p2fc-xxr8-fw3p | Liferay Portal and Liferay DXP Vulnerable to CSRF via the Layout Module |
References
History
Tue, 22 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Liferay
Published:
Updated: 2024-10-22T15:51:16.440Z
Reserved: 2023-06-12T01:29:57.068Z
Link: CVE-2023-35030
Updated: 2024-08-02T16:17:04.236Z
Status : Modified
Published: 2023-06-15T05:15:09.857
Modified: 2024-11-21T08:07:50.727
Link: CVE-2023-35030
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA