CVE-2023-33945

MEDIUM

Liferay Portal/DXP <7.4.3.17/7.4 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.4.3.17, and Liferay DXP 7.3 before update 6, and 7.4 before update 18 allows attackers to execute arbitrary SQL commands via the name of a database table's primary key index. This vulnerability is only exploitable when chained with other attacks. To exploit this vulnerability, the attacker must modify the database and wait for the application to be upgraded.

References (1)

Core 1

Scores

CVSS v3 6.4
EPSS 0.0036
EPSS Percentile 58.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (4)
com.liferay.portal/release.portal.bom 7.3.1 - 7.4.3.18Maven
liferay/digital_experience_platform 7.3 update1 (5 CPE variants)
liferay/digital_experience_platform 7.4 update1 (17 CPE variants)
liferay/liferay_portal 7.3.1 - 7.3.7
Published May 24, 2023
Tracked Since Feb 18, 2026