CVE-2020-7961

Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).

  • Published Mar 20, 2020
  • CVSS 9.8 critical
  • 99.9% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • A Metasploit module exploits it
  • A fix is available

CVE-2020-7961 at the National Vulnerability Database