vendor:
Liferay Portal
by:
fu2x2000
9.8
CVSS
CRITICAL
Insecure Permissions
264
CWE
Product Name: Liferay Portal
Affected Version From: Liferay Portal 6.2.5
Affected Version To: Liferay Portal 6.2.5 or later
Patch Exists: NO
Related CWE: CVE-2021-33990
CPE: a:liferay:liferay_portal:6.2.5
Platforms Tested:
2021
Liferay Portal 6.2.5 – Insecure Permissions
An attacker can exploit this vulnerability by sending a specially crafted request to the vulnerable server. This can allow the attacker to upload malicious files to the server, which can be used to gain access to the server.
Mitigation:
Restrict access and user groups