Логотип exploitDog
bind:CVE-2024-8980
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-8980

Количество 2

Количество 2

nvd логотип

CVE-2024-8980

больше 1 года назад

The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack 102 and 6.2 GA through fix pack 173 does not sufficiently protect against Cross-Site Request Forgery (CSRF) attacks, which allows remote attackers to execute arbitrary Groovy script via a crafted URL or a XSS vulnerability.

CVSS3: 9.6
EPSS: Низкий
github логотип

GHSA-chj2-4vg7-hhg3

больше 1 года назад

Liferay Portal and Liferay DXP Vulnerable to CSRF in the Script Console

CVSS3: 9.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-8980

The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack 102 and 6.2 GA through fix pack 173 does not sufficiently protect against Cross-Site Request Forgery (CSRF) attacks, which allows remote attackers to execute arbitrary Groovy script via a crafted URL or a XSS vulnerability.

CVSS3: 9.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-chj2-4vg7-hhg3

Liferay Portal and Liferay DXP Vulnerable to CSRF in the Script Console

CVSS3: 9.6
0%
Низкий
больше 1 года назад

Уязвимостей на страницу