CST-7057 CSRF vulnerability with comments

Description

In Liferay Portal 7.0 CE GA7, A cross-site request forgery (CSRF) vulnerability exist with comments. An attacker can potentially exploit this security vulnerability to add comments on behalf of a user.

Severity

Severity 2

Fixed Version(s)

Publication date: Wed, 04 Jul 2018 08:06:00 +0000

Security advisories for Liferay's enterprise offerings (e.g., Liferay DXP) are only listed here since 2023. Historial advisories are availabe in the Help Center.