QID 731202
Date Published: 2024-02-26
QID 731202: Liferay Portal Multiple Vulnerabilities (CVE-2021-29038,CVE-2021-29050)
Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.
CVE-2021-29038: Liferay Portal does not obfuscate password reminder answers, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user's password reminder answers.
CVE-2021-29050: A Cross-Site Request Forgery (CSRF) vulnerability in the terms of use page in Liferay Portal allows remote attackers to accept the site's terms of use via social engineering and enticing the user to visit a malicious page.
Affected Versions:
Liferay Portal from version 7.3.0 to 7.3.5.
Liferay Portal 7.2.0 and 7.2.1.
Liferay Portal, older unsupported versions.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Liferay Portal in the response banner.
Successful exploitation of this vulnerability allows attackers to use man-in-the-middle or shoulder surfing attacks and remote attackers to accept the site's terms of use via social engineering.
- Liferay Portal(CVE-2021-29038) -
liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2021-29038 - Liferay Portal(CVE-2021-29050) -
liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2021-29050
CVEs related to QID 731202
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Liferay Portal |
|