VendorsLiferayliferay_portal7.1.2
Vulnerabilities

Liferay Portal 7.1.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2019-16891
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
Published 2019-10-04 · Modified
9.8EPSS 0.447
CVE-2019-11444
An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be executed via a [command].execute() call, as demonstrated by "def cmd =" in the ServerAdminPortlet_script value to group/control_panel/manage. Valid credentials for an application administrator user account are required. NOTE: The developer disputes this as a vulnerability since it is a feature for administrators to run groovy scripts and therefore not a design flaw
Published 2019-04-22 · Modified
9.01 PoCEPSS 0.126