CRITICAL🇵🇱 Wersja polska

CVE-2024-8980

CVSS 9.6v3.1pub. 2024-10-22upd. 2024-12-10

The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack 102 and 6.2 GA through fix pack 173 does not sufficiently protect against Cross-Site Request Forgery (CSRF) attacks, which allows remote attackers to execute arbitrary Groovy script via a crafted URL or a XSS vulnerability.

🤖 AI Analysis
How it works

An attacker can trick a logged-in user (e.g., an administrator) into visiting a crafted URL or page containing malicious XSS code, which in the background sends an unauthorized request to Script Console. Since the application does not properly verify the CSRF token, the request is accepted and executed in the context of the victim's session. As a result, any Groovy script is executed server-side with the privileges of the logged-in user.

Impact

An attacker can execute arbitrary server-side code in the Liferay environment, potentially leading to complete application takeover, data theft, content modification, or further lateral movement in the infrastructure.

Mitigation & patch

Apply patches available from the vendor according to references published at https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-8980. Until the patch is implemented, restrict access to Script Console exclusively to trusted, authenticated administrators and consider blocking access to this function at the firewall or network access control level.

Who is affected

Liferay Portal 7.0.0 – 7.4.3.101; Liferay DXP 2023.Q3.1 – 2023.Q3.4, 7.4 GA – update 92, 7.3 GA – update 35, 7.2 GA – fix pack 20, 7.1 GA – fix pack 28, 7.0 GA – fix pack 102, 6.2 GA – fix pack 173

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Liferay Digital Experience Platform

    APP
    Liferay
    7.37.42023.q3.1 – 2023.q3.5 (excl.)6.2 – 7.2
  • Liferay Portal

    APP
    Liferay
    7.3.0 – 7.3.77.4.0 – 7.4.3.102 (excl.)7.0.0 – 7.0.6 (excl.)7.1.0 – 7.1.3 (excl.)7.2.0 – 7.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2020-7961CRITICAL9.8⚠ KEVPL ✓same product

RCE przez deserializację w Liferay Portal via JSONWS

CVE-2024-38002CRITICAL9.0PL ✓same product

RCE w komponencie workflow Liferay Portal i DXP — brak weryfikacji uprawnień

CVE-2023-42496CRITICAL9.6PL ✓same product

Reflected XSS w Liferay Portal i DXP na stronie przypisywania ról

CVE-2023-40191CRITICAL9.0PL ✓same product

Reflected XSS w ustawieniach kont Liferay Portal i DXP

CVE-2023-42498CRITICAL9.6PL ✓same product

Reflected XSS w ekranie Language Override w Liferay Portal i DXP