Security Advisory

CVE-2020-15839

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-09-22 17:27:49
Last updated 2024-08-04 13:30:22
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.