VulnerabilityModified
CVE-2008-0182
Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated users via the Shutdown message.
MEDIUM 4.3EPSS 0.60%
Does this matter?
Lower severity and a low EPSS score (0.60%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated users via the Shutdown message.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- liferay/liferay enterprise portal
- Source
- cret@cert.org
References
- http://secunia.com/advisories/28742Vendor Advisory
- http://support.liferay.com/browse/LEP-4739
- http://www.kb.cert.org/vuls/id/767825US Government Resource
- http://secunia.com/advisories/28742Vendor Advisory
- http://support.liferay.com/browse/LEP-4739
- http://www.kb.cert.org/vuls/id/767825US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.