CVEs Blog | G5 Cyber Security

CVE-2020-15840 – In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.

In Liferay Portal before 7.3.1, Liferay Portal 6.2 EE, and Liferay DXP 7.2, DXP 7.1 and DXP 7.0, the property ‘portlet.resource.id.banned.paths.regexp’ can be bypassed with doubled encoded URLs.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15840

Reference (s):

Exit mobile version