Логотип exploitDog
bind:CVE-2024-26265
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-26265

Количество 2

Количество 2

nvd логотип

CVE-2024-26265

почти 2 года назад

The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions relies on a request parameter to limit the size of files that can be uploaded, which allows remote authenticated users to upload arbitrarily large files to the system's temp folder by modifying the `maxFileSize` parameter.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-29xx-fhff-36m7

почти 2 года назад

Liferay Portal vulnerable to Denial of Service

CVSS3: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-26265

The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions relies on a request parameter to limit the size of files that can be uploaded, which allows remote authenticated users to upload arbitrarily large files to the system's temp folder by modifying the `maxFileSize` parameter.

CVSS3: 5
1%
Низкий
почти 2 года назад
github логотип
GHSA-29xx-fhff-36m7

Liferay Portal vulnerable to Denial of Service

CVSS3: 5
1%
Низкий
почти 2 года назад

Уязвимостей на страницу