CVE-2024-26271: CSRF
Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update 32 through update 36 allows remote attackers to (1) change user passwords, (2) shut down the server, (3) execute arbitrary code in the scripting console, (4) and perform other administrative actions via the comliferaymyaccountwebportletMyAccountPortletbackURL parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26271?
CVE-2024-26271 has been classified as a high-severity cross-site request forgery (CSRF) vulnerability.
How do I fix CVE-2024-26271?
To fix CVE-2024-26271, upgrade to a patched version of Liferay Portal or Liferay DXP as specified in the vendor's security advisory.
Which versions are affected by CVE-2024-26271?
CVE-2024-26271 affects Liferay Portal versions 7.4.3.75 to 7.4.3.111 and Liferay DXP versions 2023.Q4.0 to 2023.Q4.2 among others.
What type of vulnerability is CVE-2024-26271?
CVE-2024-26271 is a cross-site request forgery (CSRF) vulnerability.
Who can exploit CVE-2024-26271?
Remote attackers can exploit CVE-2024-26271 to change user credentials and other settings.