CVE-2023-33945

SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.4.3.17, and Liferay DXP 7.3 before update 6, and 7.4 before update 18 allows attackers to execute arbitrary SQL commands via the name of a database table's primary key index. This vulnerability is only exploitable when chained with other attacks. To exploit this vulnerability, the attacker must modify the database and wait for the application to be upgraded.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.4 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
LiferayCNA
6.4 MEDIUM
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
VendorProductVersion
liferaydigital_experience_platform
7.3:update1
liferaydigital_experience_platform
7.3:update2
liferaydigital_experience_platform
7.3:update3
liferaydigital_experience_platform
7.3:update4
liferaydigital_experience_platform
7.3:update5
liferaydigital_experience_platform
7.4:update1
liferaydigital_experience_platform
7.4:update10
liferaydigital_experience_platform
7.4:update11
liferaydigital_experience_platform
7.4:update12
liferaydigital_experience_platform
7.4:update13
liferaydigital_experience_platform
7.4:update14
liferaydigital_experience_platform
7.4:update15
liferaydigital_experience_platform
7.4:update16
liferaydigital_experience_platform
7.4:update17
liferaydigital_experience_platform
7.4:update2
liferaydigital_experience_platform
7.4:update3
liferaydigital_experience_platform
7.4:update4
liferaydigital_experience_platform
7.4:update5
liferaydigital_experience_platform
7.4:update6
liferaydigital_experience_platform
7.4:update7
liferaydigital_experience_platform
7.4:update8
liferaydigital_experience_platform
7.4:update9
liferayliferay_portal
7.3.1 ≤
𝑥
≤ 7.3.7
liferayliferay_portal
7.4.0 ≤
𝑥
≤ 7.4.3.17
𝑥
= Vulnerable software versions