com.liferay:com.liferay.portal.dao.db@5.0.8 vulnerabilities

  • latest version

    5.0.35

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    2 months ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the com.liferay:com.liferay.portal.dao.db package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    SQL Injection

    Affected versions of this package are vulnerable to SQL Injection due to improper user-input sanitization. This allows attackers to execute arbitrary SQL commands via the name of a database table's primary key index.

    Note:

    This vulnerability is only exploitable when chained with other attacks. To exploit this vulnerability, the attacker must modify the database and wait for the application to be upgraded.

    How to fix SQL Injection?

    Upgrade com.liferay:com.liferay.portal.dao.db to version 5.0.13 or higher.

    [,5.0.13)