Vulnerability Description
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not demonstrate how an unauthorized user can upload a file.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Liferay | Liferay Portal | 6.2.5 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/171701/Liferay-Portal-6.2.5-Insecure-PermisExploitThird Party AdvisoryVDB Entry
- https://github.com/fu2x2000/Liferay_exploit_PocExploitThird Party Advisory
- http://packetstormsecurity.com/files/171701/Liferay-Portal-6.2.5-Insecure-PermisExploitThird Party AdvisoryVDB Entry
- https://github.com/fu2x2000/Liferay_exploit_PocExploitThird Party Advisory
FAQ
What is CVE-2021-33990?
CVE-2021-33990 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfol...
How severe is CVE-2021-33990?
CVE-2021-33990 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-33990?
Check the references section above for vendor advisories and patch information. Affected products include: Liferay Liferay Portal.