Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is...
High severity
Unreviewed
Published
Jan 29, 2022
to the GitHub Advisory Database
•
Updated Mar 21, 2024
Description
Published by the National Vulnerability Database
Jan 28, 2022
Published to the GitHub Advisory Database
Jan 29, 2022
Last updated
Mar 21, 2024
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject commands through the Gogo Shell module to execute any OS command on the Liferay Portal Sever.
References