Количество 2
Количество 2
CVE-2023-33948
больше 2 лет назад
The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downloaded from a Form, which allows remote attackers to download any file from Document and Media via a crafted URL.
CVSS3: 5.3
EPSS: Низкий
GHSA-w6f8-mxf5-4vf8
больше 2 лет назад
Missing authorization in Liferay portal
CVSS3: 7.5
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-33948 The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downloaded from a Form, which allows remote attackers to download any file from Document and Media via a crafted URL. | CVSS3: 5.3 | 0% Низкий | больше 2 лет назад | |
GHSA-w6f8-mxf5-4vf8 Missing authorization in Liferay portal | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу
20