The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack 102 and 6.2 GA through fix pack 173 does not sufficiently protect against Cross-Site Request Forgery (CSRF) attacks, which allows remote attackers to execute arbitrary Groovy script via a crafted URL or a XSS vulnerability.
An attacker can trick a logged-in user (e.g., an administrator) into visiting a crafted URL or page containing malicious XSS code, which in the background sends an unauthorized request to Script Console. Since the application does not properly verify the CSRF token, the request is accepted and executed in the context of the victim's session. As a result, any Groovy script is executed server-side with the privileges of the logged-in user.
An attacker can execute arbitrary server-side code in the Liferay environment, potentially leading to complete application takeover, data theft, content modification, or further lateral movement in the infrastructure.
Apply patches available from the vendor according to references published at https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-8980. Until the patch is implemented, restrict access to Script Console exclusively to trusted, authenticated administrators and consider blocking access to this function at the firewall or network access control level.
Liferay Portal 7.0.0 – 7.4.3.101; Liferay DXP 2023.Q3.1 – 2023.Q3.4, 7.4 GA – update 92, 7.3 GA – update 35, 7.2 GA – fix pack 20, 7.1 GA – fix pack 28, 7.0 GA – fix pack 102, 6.2 GA – fix pack 173
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HLiferay Digital Experience Platform
APPLiferay7.37.42023.q3.1 – 2023.q3.5 (excl.)6.2 – 7.2Liferay Portal
APPLiferay7.3.0 – 7.3.77.4.0 – 7.4.3.102 (excl.)7.0.0 – 7.0.6 (excl.)7.1.0 – 7.1.3 (excl.)7.2.0 – 7.2.1
Related vulnerabilities
RCE przez deserializację w Liferay Portal via JSONWS
RCE w komponencie workflow Liferay Portal i DXP — brak weryfikacji uprawnień
Reflected XSS w Liferay Portal i DXP na stronie przypisywania ról
Reflected XSS w ustawieniach kont Liferay Portal i DXP
Reflected XSS w ekranie Language Override w Liferay Portal i DXP