XML External Entity injection in Liferay Enterprise Portal and Liferay DXP - CVE-2024-25606
Published: February 21, 2024
Vulnerability details
The vulnerability allows a remote user to compromsie the target system.
The vulnerability exists due to insufficient validation of user-supplied XML input. A remote administrator can pass a specially crafted XML code to the affected application and obtain sensitive information or consume system resources via the Java2WsddTask._format method.
Affected software
Liferay DXP
How to mitigate CVE-2024-25606
Liferay DXP - addressed in versions 7.2 fix pack 20, 7.3 update 12, 7.4 update 4