Description
Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2018-2599 Vulnerability (CVE-2018-2599)
WordPress Plugin Ultimate Maps by Supsystic SQL Injection (1.1.12)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5498)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-14630)