Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-33945


SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.4.3.17, and Liferay DXP 7.3 before update 6, and 7.4 before update 18 allows attackers to execute arbitrary SQL commands via the name of a database table's primary key index. This vulnerability is only exploitable when chained with other attacks. To exploit this vulnerability, the attacker must modify the database and wait for the application to be upgraded.


Published

2023-05-24T16:15:09.760

Last Modified

2024-11-21T08:06:15.860

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-89
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application liferay digital_experience_platform 7.3 Yes
Application liferay digital_experience_platform 7.3 Yes
Application liferay digital_experience_platform 7.3 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay digital_experience_platform 7.4 Yes
Application liferay liferay_portal ≤ 7.4.3.17 Yes

References