← Back

CVE-2023-35030

nvd nist
Published: Jun 15, 2023Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to execute arbitrary code in the scripting console via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.

Affected (8)

2 products
Dxp
Liferay Portal
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
Version 7.4 update_70
Version 7.4 update_71
Version 7.4 update_72
Version 7.4 update_73
Version 7.4 update_74
Version 7.4 update_75
Version 7.4 update_76
From 7.4.3.70 to 7.4.3.77

Timeline

No history available yet.