CVE-2023-33945
SQL injection in Liferay Portal
8.1
HIGH
CVSS 3.1
EPSS 0.65%
Description
SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.4.3.17, and Liferay DXP 7.3 before update 6, and 7.4 before update 18 allows attackers to execute arbitrary SQL commands via the name of a database table's primary key index. This vulnerability is only exploitable when chained with other attacks. To exploit this vulnerability, the attacker must modify the database and wait for the application to be upgraded.
How to fix CVE-2023-33945
To remediate CVE-2023-33945, upgrade the affected package to a fixed version below.
- —no fix listed
- —upgrade to 7.4.3.18 or later
Is CVE-2023-33945 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 7.3.0, <= 7.3.0, >= 7.4.0, <= 7.4.0 | >= 7.3-fix.0, <= 7.3-fix.0, >= 7.3-fix.0, <= 7.3-fix.0, >= 7.4-update1.0, <= 7.4-update1.0
- >= 7.3.1, < 7.4.3.18
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.1 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |