cbcvebase.
CVE-2021-33990
published 2023-04-16

CVE-2021-33990: Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the…

PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
11.92%
95.7th percentile
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not demonstrate how an unauthorized user can upload a file.

Affected

1 ranges
VendorProductVersion rangeFixed in
liferayliferay_portal

Detection & IOCsextracted from sources · hover to see the quote

path/html/js/editor/ckeditor/editor/filemanager/browser/liferay/frmfolders.html
commandCommand=FileUpload&Type=File&CurrentFolder=/
  • Use the Google dork to identify exposed Liferay instances: search for pages NOT containing the CKEditor filemanager browser path in the URL.
  • Monitor HTTP requests containing the query parameters 'Command=FileUpload', 'Type=File', and 'CurrentFolder=/' targeting Liferay Portal instances, as these indicate an attempted file upload exploitation.
  • ·The vendor disputes the severity of this CVE, stating the exploit only demonstrates that frmfolders.html is accessible and does not prove an unauthorized user can actually upload a file. Detections based on path accessibility alone may produce false positives without confirming actual file upload capability.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.