Description
Liferay Portal before 7.3.0, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17, and 7.2 before fix pack 5, allows man-in-the-middle attackers to execute arbitrary code via crafted serialized payloads, because of insecure deserialization.
Remediation
References
Related Vulnerabilities
Drupal Core 6.x Multiple Vulnerabilities (6.0 - 6.2)
Dolibarr Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-14240)
WordPress 3.9.x Denial of Service Vulnerability (3.9 - 3.9.23)
Django URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-14574)