2020-06-08 11:00:22 +08:00
..
2020-06-08 11:00:22 +08:00
2020-04-26 18:09:17 +08:00

CVE-2020-7961 Liferay Portal Java Unmarshalling via JSONWS RCE

Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).

FOFA query rule: app="Liferay"

Demo