Description
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).
Remediation
References
Related Vulnerabilities
WordPress Plugin Product Catalog Multiple SQL Injection Vulnerabilities (2.1)
WordPress Improper Input Validation Vulnerability (CVE-2018-1000773)
WordPress Plugin URL Cloak & Encrypt Cross-Site Scripting (2.0)
Apache HTTP Server Insertion of Sensitive Information into Log File Vulnerability (CVE-2001-1556)
WordPress Plugin SrbTransLatin Multiple Vulnerabilities (1.46)