CVE-2020-15839: Malicious File Upload
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-15839.
What is the severity level of CVE-2020-15839?
The severity level of CVE-2020-15839 is medium (6.5).
Which software versions are affected by CVE-2020-15839?
Liferay Portal before 7.3.3, Liferay DXP 7.1 before fix pack 18, and Liferay DXP 7.2 before fix pack 6 are affected by CVE-2020-15839.
How can remote authenticated users exploit this vulnerability?
Remote authenticated users can exploit CVE-2020-15839 by conducting denial-of-service attacks through uploading large files in a multipart/form-data POST action.
Where can I find more information about CVE-2020-15839?
You can find more information about CVE-2020-15839 in the following references: [Reference 1](https://issues.liferay.com/browse/LPE-17029), [Reference 2](https://issues.liferay.com/browse/LPE-17055), [Reference 3](https://portal.liferay.dev/learn/security/known-vulnerabilities).