vendor:
Liferay Portal
by:
Berk Dusunur
9.8
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: Liferay Portal
Affected Version From: 6.0.2
Affected Version To: 6.0.2
Patch Exists: YES
Related CWE: N/A
CPE: a:liferay:liferay_portal:6.0.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: MacOS
2020
Liferay CE Portal 6.0.2 – Remote Command Execution
A vulnerability in Liferay CE Portal 6.0.2 allows an attacker to execute arbitrary commands on the target system. The vulnerability exists due to improper validation of user-supplied input in the application. An attacker can exploit this vulnerability by sending a specially crafted payload to the application. This will allow the attacker to execute arbitrary commands on the target system.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update their systems to the latest version of the software.