Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update 32 through update 36 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the _com_liferay_my_account_web_portlet_MyAccountPortlet_backURL parameter.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Oct 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Liferay digital Experience Platform
Liferay liferay Portal |
|
CPEs | cpe:2.3:a:liferay:digital_experience_platform:2023:q3.1:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:2023:q3.5:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:2023:q4.0:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:2023:q4.2:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update32:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update33:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update34:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update35:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update75:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update81:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update82:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update83:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update84:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update85:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update86:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update92:*:*:*:*:*:* cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Liferay digital Experience Platform
Liferay liferay Portal |
Tue, 22 Oct 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Liferay
Liferay dxp Liferay portal |
|
CPEs | cpe:2.3:a:liferay:dxp:-:*:*:*:*:*:*:* cpe:2.3:a:liferay:portal:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Liferay
Liferay dxp Liferay portal |
|
Metrics |
ssvc
|
Tue, 22 Oct 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update 32 through update 36 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the _com_liferay_my_account_web_portlet_MyAccountPortlet_backURL parameter. | |
Weaknesses | CWE-352 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Liferay
Published: 2024-10-22T14:06:16.533Z
Updated: 2024-10-22T20:07:01.935Z
Reserved: 2024-02-15T07:44:36.776Z
Link: CVE-2024-26271
Vulnrichment
Updated: 2024-10-22T20:06:33.866Z
NVD
Status : Analyzed
Published: 2024-10-22T15:15:05.523
Modified: 2024-10-30T15:04:11.867
Link: CVE-2024-26271
Redhat
No data.