← Vulnerability feed

Vulnerability record · CVE-2024-26273 · published 22 October 2024

CVE-2024-26273: Liferay digital experience platform cross-site request forgery vulnerability

Liferay · Digital Experience Platform

Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 update 29 through update 35 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the _com_liferay_commerce_catalog_web_internal_portlet_CommerceCatalogsPortlet_redirect parameter.

8.8 CVSS 3.1 High EPSS 0.36% · top 73.3% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 update 29 through update 35 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the _com_liferay_commerce_catalog_web_internal_portlet_CommerceCatalogsPortlet_redirect parameter.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-26273 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-7961Liferay Portal JSONWS deserialization allows remote code executionLiferay Portal before 7.2.1 CE GA2 deserializes untrusted data received through its JSON web services (JSONWS) endpoints. Because the input is not sa…KEVEPSS 100%analysed9.8CVE-2021-33990Liferay portal os command injection vulnerabilityLiferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue b…EPSS 12%9.8CVE-2022-42120Liferay dxp sql injection vulnerabilityA SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before up…EPSS 0.78%9.8CVE-2022-42122Liferay dxp sql injection vulnerabilityA SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to…EPSS 0.77%9.8CVE-2019-16891Liferay Portal CE JSON deserialization remote command executionLiferay Portal CE 6.2.5 deserializes untrusted JSON payloads, allowing an unauthenticated remote attacker to execute commands. The flaw is a CWE-502 …EPSS 45%analysed8.8CVE-2024-38002Liferay digital experience platform missing authorization vulnerabilityThe workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA th…EPSS 0.61%8.8CVE-2024-26271Liferay digital experience platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 thro…EPSS 0.36%8.8CVE-2024-26272Liferay digital experience platform cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 throu…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2024-26273), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.