CVE-2021-33990

CRITICAL

Liferay Portal - OS Command Injection

Title source: rule

Description

Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not demonstrate how an unauthorized user can upload a file.

Exploits (1)

exploitdb SCANNER
by Fu2x2000 · pythonwebappsjava
https://www.exploit-db.com/exploits/51244

Scores

CVSS v3 9.8
EPSS 0.6376
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78 CWE-281
Status published
Products (1)
liferay/liferay_portal 6.2.5
Published Apr 16, 2023
Tracked Since Feb 18, 2026