#VU86692 XML External Entity injection in Liferay Enterprise Portal and Liferay DXP - CVE-2024-25606
Published: February 21, 2024
Liferay Enterprise Portal
Liferay DXP
Liferay
Description
The vulnerability allows a remote user to compromsie the target system.
The vulnerability exists due to insufficient validation of user-supplied XML input. A remote administrator can pass a specially crafted XML code to the affected application and obtain sensitive information or consume system resources via the Java2WsddTask._format method.