Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g7vw-43xg-8m4h

Опубликовано: 24 мая 2023
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

SQL injection in Liferay Portal

SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.4.3.17, and Liferay DXP 7.3 before update 6, and 7.4 before update 18 allows attackers to execute arbitrary SQL commands via the name of a database table's primary key index. This vulnerability is only exploitable when chained with other attacks. To exploit this vulnerability, the attacker must modify the database and wait for the application to be upgraded.

Пакеты

Наименование

com.liferay.portal:release.portal.bom

maven
Затронутые версииВерсия исправления

>= 7.3.1, < 7.4.3.18

7.4.3.18

EPSS

Процентиль: 51%
0.00282
Низкий

8.1 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 6.4
nvd
больше 2 лет назад

SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.4.3.17, and Liferay DXP 7.3 before update 6, and 7.4 before update 18 allows attackers to execute arbitrary SQL commands via the name of a database table's primary key index. This vulnerability is only exploitable when chained with other attacks. To exploit this vulnerability, the attacker must modify the database and wait for the application to be upgraded.

EPSS

Процентиль: 51%
0.00282
Низкий

8.1 High

CVSS3

Дефекты

CWE-89