CVE-2020-7961

CRITICAL KEV NUCLEI

Liferay Portal <7.2.1 CE GA2 - Code Injection

Title source: llm

Description

Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).

Exploits (16)

exploitdb WORKING POC VERIFIED
by Metasploit · remotejava
https://www.exploit-db.com/exploits/48332
nomisec WORKING POC 119 stars
by mzer0one · remote
https://github.com/mzer0one/CVE-2020-7961-POC
nomisec WORKING POC 18 stars
by ShutdownRepo · remote
https://github.com/ShutdownRepo/CVE-2020-7961
nomisec WORKING POC 5 stars
by thelostworldFree · remote
https://github.com/thelostworldFree/CVE-2020-7961-payloads
nomisec WORKING POC 2 stars
by CrackerCat · remote
https://github.com/CrackerCat/CVE-2020-7961-Mass
nomisec WRITEUP
by neverhavenamee · remote
https://github.com/neverhavenamee/CVE-2020-7961
nomisec NO CODE
by manrop2702 · poc
https://github.com/manrop2702/CVE-2020-7961
nomisec SUSPICIOUS
by pashayogi · poc
https://github.com/pashayogi/CVE-2020-7961-Mass
nomisec WORKING POC
by Alaa-abdulridha · poc
https://github.com/Alaa-abdulridha/POC-CVE-2020-7961-Token-iterate
nomisec SCANNER
by Alaa-abdulridha · poc
https://github.com/Alaa-abdulridha/GLiferay-CVE-2020-7961-golang
vulncheck_xdb WORKING POC
remote
https://github.com/random-robbie/liferay-pwn
metasploit WORKING POC EXCELLENT
by Markus Wulftange, Thomas Etrillard, wvu · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/liferay_java_unmarshalling.rb

Nuclei Templates (1)

Liferay Portal Unauthenticated < 7.2.1 CE GA2 - Remote Code Execution
CRITICALby dwisiswant0
Shodan: http.favicon.hash:129457226 || cpe:"cpe:2.3:a:liferay:liferay_portal"
FOFA: icon_hash=129457226

Scores

CVSS v3 9.8
EPSS 0.9440
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-01-14
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2022-5527
CWE
CWE-502
Status published
Products (2)
com.liferay.portal/com.liferay.portal.kernel 0 - 4.35.3Maven
liferay/liferay_portal < 7.2.1
Published Mar 20, 2020
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026