QID 731014
Date Published: 2023-12-26
QID 731014: Liferay Portal SQL Injection Vulnerability
SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal attackers to execute arbitrary SQL commands via the name of a database table's primary key index. This vulnerability is only exploitable when chained with other attacks. To exploit this vulnerability, the attacker must modify the database and wait for the application to be upgraded.
Affected Versions:
Liferay Portal 7.3.1 - 7.3.7
Liferay Portal 7.4.0 - 7.4.3.17
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Liferay Portal in response banner.
Successful exploit may allow attackers to execute arbitrary SQL commands via the name of a database table's primary key index.
Vendor has released patch. For more info please refer to Liferay Portal Security Advisory
CVEs related to QID 731014
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-33945 |
|