Логотип exploitDog
bind:CVE-2025-3594
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-3594

Количество 2

Количество 2

nvd логотип

CVE-2025-3594

8 месяцев назад

Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older unsupported versions allows remote attackers to (1) add files to arbitrary locations on the server and (2) download and execute arbitrary files from the download server via the `_com_liferay_server_admin_web_portlet_ServerAdminPortlet_jarName` parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-p73j-gpcq-49h8

8 месяцев назад

Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-3594

Path traversal vulnerability with the downloading and installation of Xuggler in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 34, and older unsupported versions allows remote attackers to (1) add files to arbitrary locations on the server and (2) download and execute arbitrary files from the download server via the `_com_liferay_server_admin_web_portlet_ServerAdminPortlet_jarName` parameter.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-p73j-gpcq-49h8

Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler

0%
Низкий
8 месяцев назад

Уязвимостей на страницу