Description
Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to access files outside of com.liferay.headless.discovery.web/META-INF/resources via the `parameter` parameter.
Remediation
References
Related Vulnerabilities
Moodle Insertion of Sensitive Information into Log File Vulnerability (CVE-2018-10889)
Dolibarr Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-11825)
WordPress Plugin Another WordPress Classifieds Multiple Vulnerabilities (2.2.1)
WordPress Plugin Visitor Traffic Real Time Statistics Cross-Site Request Forgery (1.12)