Vulnerability Database

289,784

Total vulnerabilities in the database

CVE-2021-33335

Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows remote authenticated users with permission to update/edit users to take over a company administrator user account by editing the company administrator user.

  • Published: Aug 4, 2021
  • Updated: Apr 14, 2023
  • CVE: CVE-2021-33335
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.2
  • AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: Medium
  • Score: 6.5
  • AV:N/AC:L/Au:S/C:P/I:P/A:P

CWEs:

Software From Fixed in
liferay / liferay_portal 7.0.3 7.3.5
liferay / digital_experience_platform 7.2 7.2.x
liferay / digital_experience_platform 7.2-fix_pack_1 7.2-fix_pack_1.x
liferay / digital_experience_platform 7.2-fix_pack_2 7.2-fix_pack_2.x
liferay / digital_experience_platform 7.2-fix_pack_3 7.2-fix_pack_3.x
liferay / digital_experience_platform 7.2-fix_pack_5 7.2-fix_pack_5.x
liferay / digital_experience_platform 7.2-fix_pack_4 7.2-fix_pack_4.x
liferay / digital_experience_platform 7.1-fix_pack_6 7.1-fix_pack_6.x
liferay / digital_experience_platform 7.1-fix_pack_9 7.1-fix_pack_9.x
liferay / digital_experience_platform 7.1-fix_pack_10 7.1-fix_pack_10.x
liferay / digital_experience_platform 7.1-fix_pack_11 7.1-fix_pack_11.x
liferay / digital_experience_platform 7.1-fix_pack_12 7.1-fix_pack_12.x
liferay / digital_experience_platform 7.1-fix_pack_13 7.1-fix_pack_13.x
liferay / digital_experience_platform 7.1-fix_pack_14 7.1-fix_pack_14.x
liferay / digital_experience_platform 7.1-fix_pack_15 7.1-fix_pack_15.x
liferay / digital_experience_platform 7.1-fix_pack_16 7.1-fix_pack_16.x
liferay / digital_experience_platform 7.1-fix_pack_4 7.1-fix_pack_4.x
liferay / digital_experience_platform 7.1 7.1.x
liferay / digital_experience_platform 7.1-fix_pack_17 7.1-fix_pack_17.x
liferay / digital_experience_platform 7.1-fix_pack_7 7.1-fix_pack_7.x
liferay / digital_experience_platform 7.1-fix_pack_8 7.1-fix_pack_8.x
liferay / digital_experience_platform 7.1-fix_pack_1 7.1-fix_pack_1.x
liferay / digital_experience_platform 7.1-fix_pack_2 7.1-fix_pack_2.x
liferay / digital_experience_platform 7.1-fix_pack_3 7.1-fix_pack_3.x
liferay / digital_experience_platform 7.1-fix_pack_5 7.1-fix_pack_5.x
liferay / digital_experience_platform 7.2-fix_pack_6 7.2-fix_pack_6.x
liferay / digital_experience_platform 7.2-fix_pack_7 7.2-fix_pack_7.x
liferay / digital_experience_platform 7.2-fix_pack_8 7.2-fix_pack_8.x
liferay / digital_experience_platform 7.1-fix_pack_18 7.1-fix_pack_18.x
liferay / digital_experience_platform 7.1-fix_pack_19 7.1-fix_pack_19.x