CVE-2024-26271

Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update 32 through update 36 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the _com_liferay_my_account_web_portlet_MyAccountPortlet_backURL parameter.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
LiferayCNA
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 32%
VendorProductVersion
liferaydigital_experience_platform
2023.q3.1 ≤
𝑥
< 2023.q3.6
liferaydigital_experience_platform
2023.q4.0 ≤
𝑥
< 2023.q4.3
liferaydigital_experience_platform
7.3:update32
liferaydigital_experience_platform
7.3:update33
liferaydigital_experience_platform
7.3:update34
liferaydigital_experience_platform
7.3:update35
liferaydigital_experience_platform
7.4:update75
liferaydigital_experience_platform
7.4:update76
liferaydigital_experience_platform
7.4:update77
liferaydigital_experience_platform
7.4:update78
liferaydigital_experience_platform
7.4:update79
liferaydigital_experience_platform
7.4:update80
liferaydigital_experience_platform
7.4:update81
liferaydigital_experience_platform
7.4:update82
liferaydigital_experience_platform
7.4:update83
liferaydigital_experience_platform
7.4:update84
liferaydigital_experience_platform
7.4:update85
liferaydigital_experience_platform
7.4:update86
liferaydigital_experience_platform
7.4:update87
liferaydigital_experience_platform
7.4:update88
liferaydigital_experience_platform
7.4:update89
liferaydigital_experience_platform
7.4:update90
liferaydigital_experience_platform
7.4:update91
liferaydigital_experience_platform
7.4:update92
liferayliferay_portal
7.4.3.75 ≤
𝑥
< 7.4.3.112
𝑥
= Vulnerable software versions