Lucene search

K
prionPRIOn knowledge basePRION:CVE-2019-11444
HistoryApr 22, 2019 - 11:29 a.m.

Input validation

2019-04-2211:29:00
PRIOn knowledge base
www.prio-n.com
5

7 High

AI Score

Confidence

High

0.045 Low

EPSS

Percentile

92.5%

DISPUTED An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay’s Groovy script console to execute OS commands. Commands can be executed via a [command].execute() call, as demonstrated by “def cmd =” in the ServerAdminPortlet_script value to group/control_panel/manage. Valid credentials for an application administrator user account are required. NOTE: The developer disputes this as a vulnerability since it is a feature for administrators to run groovy scripts and therefore not a design flaw.

CPENameOperatorVersion
liferay_portaleq7.1.2 ga3

7 High

AI Score

Confidence

High

0.045 Low

EPSS

Percentile

92.5%

Related for PRION:CVE-2019-11444