QID 730147
Date Published: 2021-08-12
QID 730147: LifeRay Multiple SQL Injection Vulnerabilities
Liferay, Inc., is an open-source company that provides free documentation and paid professional service to users of its software.
Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter.
Affected Versions:
Liferay CE 7.3.5
QID detection logic:
This unauthenticated QID checks for the banner as well as the CE portal regex in the main GET query.
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code on the target system.
Solution
Update the Liferay Community Edition to the 7.3.6 or later.
Vendor References
CVEs related to QID 730147
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-29053 |
|