Cross-Site Request Forgery (CSRF) vulnerability in the terms of use page in Liferay Portal before 7.3.6, and Liferay DXP 7.3 before service pack 1, 7.2 before fix pack 11 allows remote attackers to accept the site's terms of use via social engineering and enticing the user to visit a malicious page.
History

Thu, 24 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Liferay
Liferay dxp
Liferay portal
CPEs cpe:2.3:a:liferay:dxp:-:*:*:*:*:*:*:*
cpe:2.3:a:liferay:portal:*:*:*:*:*:*:*:*
Vendors & Products Liferay
Liferay dxp
Liferay portal
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-02-20T00:00:00.000Z

Updated: 2025-04-24T15:06:41.135Z

Reserved: 2021-03-22T00:00:00.000Z

Link: CVE-2021-29050

cve-icon Vulnrichment

Updated: 2024-08-03T21:55:12.555Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-20T22:15:08.067

Modified: 2024-11-21T06:00:35.950

Link: CVE-2021-29050

cve-icon Redhat

No data.