Description
The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote attackers to use the contents of error messages to help launch another, more focused attacks via crafted inputs.
Remediation
References
Related Vulnerabilities
WordPress Plugin Form Vibes-Database Manager for Forms SQL Injection (1.4.10)
WordPress Plugin Zita Elementor Site Library Arbitrary File Upload (1.6.1)
WordPress Plugin Captain Slider Cross-Site Scripting (1.0.6)
WordPress Plugin Comment Rating 'id' Parameter SQL Injection (2.9.23)
ReviveAdserver Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-9455)