Description
CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to execute any Headless API via the `endpoint` parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Image Optimizer, Resizer and CDN-Sirv Arbitrary File Upload (7.2.6)
Squid Improper Input Validation Vulnerability (CVE-2012-5643)
MongoDb Improper Neutralization of Null Byte or NUL Character Vulnerability (CVE-2024-10921)
WordPress Plugin Facebook Button by BestWebSoft Cross-Site Scripting (2.53)