CVE-2020-15839Unrestricted File Upload in Portal

Severity
6.5MEDIUMNVD
EPSS
1.1%
top 22.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 22
Latest updateFeb 10

Description

Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

3
OSV
Unrestricted Upload of File with Dangerous Type in Liferay Portal and Liferay DXP2022-02-10
GHSA
Unrestricted Upload of File with Dangerous Type in Liferay Portal and Liferay DXP2022-02-10
CVEList
CVE-2020-15839: Liferay Portal before 72020-09-22
CVE-2020-15839 — Unrestricted File Upload in Portal | cvebase