CVE-2023-35030 is a Cross-Site Request Forgery (CSRF) vulnerability found in the Layout module's SEO configuration within Liferay Portal versions 7.4.3.70 through 7.4.3.76 and Liferay DXP 7.4 update 70 through 76. This high-severity vulnerability (CVSS 8.8) allows remote attackers, through user interaction, to execute arbitrary code in the scripting console by manipulating the '_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL' parameter. While the attack complexity is low, successful exploitation can lead to complete compromise of confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.4CPE matchmatch criteria | cpe:2.3:a:liferay:dxp:7.4:update_70:*:*:*:*:*:* | ||
7.4CPE matchmatch criteria | cpe:2.3:a:liferay:dxp:7.4:update_71:*:*:*:*:*:* | ||
7.4CPE matchmatch criteria | cpe:2.3:a:liferay:dxp:7.4:update_72:*:*:*:*:*:* | ||
7.4CPE matchmatch criteria | cpe:2.3:a:liferay:dxp:7.4:update_73:*:*:*:*:*:* | ||
7.4CPE matchmatch criteria | cpe:2.3:a:liferay:dxp:7.4:update_74:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.