Liferay Portal vulnerable to arbitrary command injection
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jul 15, 2025
Package
Affected versions
>= 5.0.0, < 6.0.6-ga
Patched versions
6.0.6-ga
Description
Published by the National Vulnerability Database
May 7, 2011
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 15, 2025
Last updated
Jul 15, 2025
Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.
References