5.0.35
3 years ago
2 months ago
Known vulnerabilities in the com.liferay:com.liferay.portal.dao.db package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to SQL Injection due to improper user-input sanitization. This allows attackers to execute arbitrary SQL commands via the name of a database table's primary key index. Note: This vulnerability is only exploitable when chained with other attacks. To exploit this vulnerability, the attacker must modify the database and wait for the application to be upgraded. How to fix SQL Injection? Upgrade | [,5.0.13) |