Description
Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 allow remote authenticated users to execute arbitrary SQL commands via the classPKField parameter to (1) CommerceChannelRelFinder.countByC_C, or (2) CommerceChannelRelFinder.findByC_C.
Severity
Severity 2
Fixed Version(s)
Publication date: Wed, 12 May 2021 02:54:00 +0000