{"api_version":"1","generated_at":"2026-07-23T05:22:03+00:00","cve":"CVE-2008-0182","urls":{"html":"https://cve.report/CVE-2008-0182","api":"https://cve.report/api/cve/CVE-2008-0182.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-0182","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-0182"},"summary":{"title":"CVE-2008-0182","description":"Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated users via the Shutdown message.","state":"PUBLISHED","assigner":"certcc","published_at":"2008-02-05 00:00:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-352","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.kb.cert.org/vuls/id/767825","name":"http://www.kb.cert.org/vuls/id/767825","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#767825","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.liferay.com/browse/LEP-4739","name":"http://support.liferay.com/browse/LEP-4739","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[#LEP-4739] Admin portlet Shutdown message has XSS and CSRF vulnerability - Liferay Issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28742","name":"http://secunia.com/advisories/28742","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Liferay Portal Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-0182","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-0182","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"182","vulnerable":"1","versionEndIncluding":"4.3.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"liferay","cpe5":"liferay_enterprise_portal","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T07:39:34.049Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"VU#767825","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/767825"},{"name":"28742","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28742"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.liferay.com/browse/LEP-4739"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated users via the Shutdown message."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2008-02-04T23:00:00.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"VU#767825","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/767825"},{"name":"28742","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28742"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.liferay.com/browse/LEP-4739"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2008-0182","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated users via the Shutdown message."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"VU#767825","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/767825"},{"name":"28742","refsource":"SECUNIA","url":"http://secunia.com/advisories/28742"},{"name":"http://support.liferay.com/browse/LEP-4739","refsource":"CONFIRM","url":"http://support.liferay.com/browse/LEP-4739"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2008-0182","datePublished":"2008-02-04T23:00:00.000Z","dateReserved":"2008-01-09T00:00:00.000Z","dateUpdated":"2024-09-17T02:27:19.192Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-02-05 00:00:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-352","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:liferay:liferay_enterprise_portal:*:*:*:*:*:*:*:*","versionEndIncluding":"4.3.6","matchCriteriaId":"68EA9FF6-2115-409D-9523-B1CA74941FB5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"182","Ordinal":"1","Title":"CVE-2008-0182","CVE":"CVE-2008-0182","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"182","Ordinal":"1","NoteData":"Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated users via the Shutdown message.","Type":"Description","Title":"CVE-2008-0182"},{"CveYear":"2008","CveId":"182","Ordinal":"2","NoteData":"2008-02-04","Type":"Other","Title":"Published"}]}}}