CVE-2023-35030: CSRF
Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to execute arbitrary code in the scripting console via the comliferaylayoutadminwebportletGroupPagesPortletbackURL parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-35030?
CVE-2023-35030 is a Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal and Liferay DXP.
How does CVE-2023-35030 affect Liferay Portal and Liferay DXP?
CVE-2023-35030 affects Liferay Portal 7.4.3.70 through 7.4.3.76 and Liferay DXP 7.4 update 70 through 76.
What is the severity of CVE-2023-35030?
CVE-2023-35030 has a severity rating of 8.8 (High).
How can remote attackers exploit CVE-2023-35030?
Remote attackers can execute arbitrary code in the scripting console via the _com_liferay_layout_admin_web_portlet_Gro...
Is there a fix available for CVE-2023-35030?
Yes, a fix is available for CVE-2023-35030. Please refer to the official reference for more information.