Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 GA through update 35 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the p_l_back_url parameter.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Oct 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Liferay digital Experience Platform
Liferay liferay Portal |
|
CPEs | cpe:2.3:a:liferay:digital_experience_platform:2023:q3.1:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:2023:q3.5:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:2023:q4.0:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:2023:q4.2:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:-:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update14:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update32:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update33:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update34:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.3:update35:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update75:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update81:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update82:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update83:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update84:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update85:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update86:*:*:*:*:*:* cpe:2.3:a:liferay:digital_experience_platform:7.4:update92:*:*:*:*:*:* cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Liferay digital Experience Platform
Liferay liferay Portal |
Tue, 22 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Liferay
Liferay dxp Liferay portal |
|
CPEs | cpe:2.3:a:liferay:dxp:*:*:*:*:*:*:*:* cpe:2.3:a:liferay:portal:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Liferay
Liferay dxp Liferay portal |
|
Metrics |
ssvc
|
Tue, 22 Oct 2024 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 GA through update 35 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the p_l_back_url parameter. | |
Weaknesses | CWE-352 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Liferay
Published: 2024-10-22T14:50:41.505Z
Updated: 2024-10-22T15:17:20.008Z
Reserved: 2024-02-15T07:44:36.776Z
Link: CVE-2024-26272
Vulnrichment
Updated: 2024-10-22T15:17:10.633Z
NVD
Status : Analyzed
Published: 2024-10-22T15:15:05.740
Modified: 2024-10-30T15:03:51.437
Link: CVE-2024-26272
Redhat
No data.