Liferay Portal Deserialization of Untrusted Data Vulnerability - CVE-2020-7961 - Vulnerability Database

Liferay Portal Deserialization of Untrusted Data Vulnerability - CVE-2020-7961

Critical
Reference: CVE-2020-7961
Title: Liferay Portal Deserialization of Untrusted Data Vulnerability
Overview:

Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).