Description
Liferay Portal through v7.2.1 and Liferay DXP through v7.2 does not correctly import users from LDAP, allowing remote attackers to prevent a legitimate user from authenticating by attempting to sign in as a user that exists in LDAP.
Remediation
References
Related Vulnerabilities
osCommerce Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2002-2019)
Drupal Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2009-2372)
WordPress Plugin WP STAGING WordPress Backup-Migration Backup Restore Arbitrary File Upload (3.4.3)
Claroline Other Vulnerability (CVE-2006-1594)
WordPress Plugin Frontend File Manager Cross-Site Request Forgery (21.3)