Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2021-33338 - Vulnerability Database

Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability - CVE-2021-33338

High
Reference: CVE-2021-33338
Title: Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability
Overview:

The Layout module in Liferay Portal 7.1.0 through 7.3.2 and Liferay DXP 7.1 before fix pack 19 and 7.2 before fix pack 6 exposes the CSRF token in URLs which allows man-in-the-middle attackers to obtain the token and conduct Cross-Site Request Forgery (CSRF) attacks via the p_auth parameter.