Description
The Liferay JSON implementation do not check if a user that call a method on a serviceClass is disabled. Usually the default administrator user, test@liferay.com, is used to create a new administrator and disabled without to change the default password, so it is possible to use it to execute JSON API calls.
Remediation
Upgrade to the latest version of Liferay.
References
Related Vulnerabilities
WordPress Plugin Passster-Password Protection Security Bypass (3.5.5.8)
WordPress Plugin Popup Maker-Popup for opt-ins, lead gen, & more Security Bypass (1.7.29)
Joomla! Core Security Bypass (2.5.0 - 3.9.27)
WordPress Plugin LearnPress-WordPress LMS Security Bypass (3.2.6.8)
WordPress Plugin Battle Suit for Divi Security Bypass (1.10.1)