CyberRota Analysis
AI analysis pending.
CVE
CVE-2020-15839
Severity
MEDIUM
CVSS
6.5
EPSS
2.16%
Original NVD Description
Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.