Description
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.
Remediation
References
Related Vulnerabilities
silverstripeCMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5087)
WordPress Plugin The Sorter SQL Injection (1.0)
WordPress 4.5.x Multiple Vulnerabilities (4.5 - 4.5.3)
WordPress CVE-2019-17673 Vulnerability (CVE-2019-17673)
WordPress Plugin Acurax On Click Pop Under Multiple Unspecified Vulnerabilities (2.2.1)