QID 730711

Date Published: 2023-02-06

QID 730711: Liferay Portal SQL Injection Vulnerability

SQL injection vulnerability in the Fragment module's PortletPreferences upgrade process in Liferay Portal 7.3.3 through 7.4.3.16 allows attackers to execute arbitrary SQL commands via a PortletPreferences namespace attribute..

Affected Versions:
Liferay Portal 7.3.3 through 7.4.3.16

QID Detection Logic (Unauthenticated): This QID checks for vulnerable version of Liferay Portal in response banner.

Successful exploit may allows attackers to execute arbitrary SQL commands via a PortletPreferences

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Vendor has released patch. For more info please refer to Liferay Portal Security Advisory

    CVEs related to QID 730711

    Software Advisories
    Advisory ID Software Component Link
    Liferay Portal URL Logo liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2022-42120