Description
Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal and Liferay DXP allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the _com_liferay_my_account_web_portlet_MyAccountPortlet_backURL parameter.
Severity
8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Affected Version(s)
- Liferay Portal 7.4.3.75 through 7.4.3.111
- Liferay DXP 2023.Q4.0 through 2023.Q4.2
- Liferay DXP 2023.Q3.1 through 2023.Q3.5
- Liferay DXP 7.4 Update 75 through Update 92
- Liferay DXP 7.3 Update 32 through Update 35
Fixed Version(s)
- Liferay Portal 7.4.3.112
- Liferay DXP 2024.Q1.1
- Liferay DXP 2023.Q4.3
- Liferay DXP 2023.Q3.6
- Liferay DXP 7.3 Update 36
Acknowledgments
This issue was reported by NDIx
Publication date: Thu, 12 Sep 2024 18:52:00 +0000