Looking for the vulnerability index of Invicti's legacy products?
Unauthenticated Remote Code Execution via JSONWS in Liferay 6.1 (LPS-88051) - Vulnerability Database

Unauthenticated Remote Code Execution via JSONWS in Liferay 6.1 (LPS-88051)

Description

A remote code execution vulnerability exists in Liferay Portal 6.1 that can be exploited via JSON web services (JSONWS).

The JSONWS servlet of Liferay Portal uses flexjson library that allows the instantiation of arbitrary classes and invocation of arbitrary setter methods.

Remediation

Upgrade to the latest version of Liferay Portal.

Related Vulnerabilities