QID 731014

Date Published: 2023-12-26

QID 731014: Liferay Portal SQL Injection Vulnerability

SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal attackers to execute arbitrary SQL commands via the name of a database table's primary key index. This vulnerability is only exploitable when chained with other attacks. To exploit this vulnerability, the attacker must modify the database and wait for the application to be upgraded.

Affected Versions:
Liferay Portal 7.3.1 - 7.3.7
Liferay Portal 7.4.0 - 7.4.3.17
QID Detection Logic (Unauthenticated): This QID checks for vulnerable version of Liferay Portal in response banner.

Successful exploit may allow attackers to execute arbitrary SQL commands via the name of a database table's primary key index.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Vendor has released patch. For more info please refer to Liferay Portal Security Advisory

    CVEs related to QID 731014

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-33945 URL Logo liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-33945