GobyVuls/CVE-2020-7961.md
2023-04-07 11:13:57 +08:00

1.6 KiB
Raw Blame History

Liferay Portal Unauthenticated 7.2.1 RCE (CVE-2020-7961)

Vulnerability Liferay Portal Unauthenticated 7.2.1 RCE (CVE-2020-7961)
Chinese name Liferay Portal 7.2.1 版本 invoke 文件远程代码执行漏洞CVE-2020-7961
CVSS core 10.0
FOFA Query (click to view the results directly) body="Powered by Liferay Portal" || header="Liferay Portal" || banner="Liferay Portal" || header="guest_language_id=" || banner="guest_language_id=" || body="Liferay.AUI" || body="Liferay.currentURL"
Number of assets affected 59885
Description Liferay Portal is a set of J2EE-based portal solutions of American Liferay Company. The program uses EJB and JMS and other technologies, and can be used as Web publishing and sharing workspace, enterprise collaboration platform, social network and so on. A code issue vulnerability exists in versions prior to Liferay Portal 7.2.1 CE GA2. A remote attacker could exploit this vulnerability to execute arbitrary code using JSON Web services.
Impact A code issue vulnerability exists in versions prior to Liferay Portal 7.2.1 CE GA2. A remote attacker could exploit this vulnerability to execute arbitrary code using JSON Web services.