QID 731168
Date Published: 2024-02-21
QID 731168: Liferay Portal Multiple Vulnerabilities (CVE-2022-45320,CVE-2024-26265)
Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.
CVE-2022-45320: Privilege escalation vulnerability in Wiki in Liferay Portal and Liferay DXP allows remote authenticated users to become the owner of a wiki page by editing the wiki page.
CVE-2024-26265: The Image Uploader module in Liferay Portal relies on a request parameter to limit the size of files that can be uploaded, which allows remote authenticated users to upload arbitrarily large files to the system's temp folder.
Affected Versions:
Liferay Portal from version 7.4.0 to 7.4.3.15.
Liferay Portal from version 7.3.0 to 7.3.7.
Liferay Portal 7.2.0 and 7.2.1.
Liferay Portal, older unsupported versions.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Liferay Portal in the response banner.
Successful exploitation of this vulnerability allows remote authenticated users to become the owner of a wiki page by editing the wiki page.
- Liferay Liferay Portal(CVE-2022-45320) -
liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2022-45320 - Liferay Liferay Portal(CVE-2024-26265) -
liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-26265
CVEs related to QID 731168
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Liferay Portal |
|