# N/A
## 漏洞概述
Liferay Portal在7.2.1 CE GA2之前的版本中存在不安全的数据反序列化问题,远程攻击者可以通过JSON Web服务(JSONWS)执行任意代码。
## 影响版本
- Liferay Portal 7.2.1 CE GA2之前的所有版本
## 漏洞细节
在Liferay Portal 7.2.1 CE GA2之前的版本中,存在对不信任数据的反序列化漏洞,可导致攻击者通过JSON Web服务(JSONWS)注入并执行任意代码。
## 影响
远程攻击者可能利用此漏洞进行代码执行,进而控制受影响的系统,造成数据泄露或系统被恶意控制的严重后果。
是否为 Web 类漏洞: 是
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | None | https://github.com/mzer0one/CVE-2020-7961-POC | POC详情 |
| 2 | None | https://github.com/wcxxxxx/CVE-2020-7961 | POC详情 |
| 3 | Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS) | https://github.com/thelostworldFree/CVE-2020-7961-payloads | POC详情 |
| 4 | None | https://github.com/shacojx/LifeRCEJsonWSTool-POC-CVE-2020-7961-Gui | POC详情 |
| 5 | Detect vulns liferay CVE-2020-7961 by Nattroc (EOG Team) | https://github.com/shacojx/GLiferay-CVE-2020-7961-golang | POC详情 |
| 6 | POC-CVE-2020-7961-Token-iterate | https://github.com/shacojx/POC-CVE-2020-7961-Token-iterate | POC详情 |
| 7 | CVE-2020–7961 Mass exploit for Script Kiddies | https://github.com/Udyz/CVE-2020-7961-Mass | POC详情 |
| 8 | Exploit script for CVE-2020-7961 | https://github.com/ShutdownRepo/CVE-2020-7961 | POC详情 |
| 9 | None | https://github.com/pashayogi/CVE-2020-7961-Mass | POC详情 |
| 10 | None | https://github.com/manrop2702/CVE-2020-7961 | POC详情 |
| 11 | None | https://github.com/NMinhTrung/LIFERAY-CVE-2020-7961 | POC详情 |
| 12 | CVE-2020–7961 Mass exploit for Script Kiddies | https://github.com/CrackerCat/CVE-2020-7961-Mass | POC详情 |
| 13 | A simple workflow that runs all liferay related nuclei templates on a given target. | https://github.com/projectdiscovery/nuclei-templates/blob/main/workflows/liferay-workflow.yaml | POC详情 |
| 14 | Liferay login panel was detected, | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/exposed-panels/liferay-portal.yaml | POC详情 |
| 15 | Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS). | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-7961.yaml | POC详情 |
| 16 | None | https://github.com/Threekiii/Awesome-POC/blob/master/CMS%E6%BC%8F%E6%B4%9E/Liferay%20Portal%20CE%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2020-7961.md | POC详情 |
| 17 | https://github.com/vulhub/vulhub/blob/master/liferay-portal/CVE-2020-7961/README.md | POC详情 | |
| 18 | None | https://github.com/neverhavenamee/CVE-2020-7961 | POC详情 |
| 19 | POC-CVE-2020-7961-Token-iterate | https://github.com/Alaa-abdulridha/POC-CVE-2020-7961-Token-iterate | POC详情 |
| 20 | Detect vulns liferay CVE-2020-7961 by Nattroc (EOG Team) | https://github.com/Alaa-abdulridha/GLiferay-CVE-2020-7961-golang | POC详情 |
暂无评论