Skip to content

Latest commit

 

History

History

CVE-2020-7961

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 

CVE-2020-7961 Liferay Portal Java Unmarshalling via JSONWS RCE

Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).

FOFA query rule: app="Liferay"

Demo