CVE-2021-33990: OS Command Injection
DISPUTED Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not demonstrate how an unauthorized user can upload a file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-33990.
What is the severity of CVE-2021-33990?
The severity of CVE-2021-33990 is critical with a severity value of 9.8.
Which version of Liferay Portal is affected by CVE-2021-33990?
Liferay Portal version 6.2.5 is affected by CVE-2021-33990.
What is the CWE ID for CVE-2021-33990?
The CWE ID for CVE-2021-33990 is CWE-281.
Are there any known exploit references for CVE-2021-33990?
Yes, there are exploit references available for CVE-2021-33990. You can find them at the following links: [http://packetstormsecurity.com/files/171701/Liferay-Portal-6.2.5-Insecure-Permissions.html](http://packetstormsecurity.com/files/171701/Liferay-Portal-6.2.5-Insecure-Permissions.html) and [https://github.com/fu2x2000/Liferay_exploit_Poc](https://github.com/fu2x2000/Liferay_exploit_Poc).