Liferay Portal and Liferay DXP Captcha Bypass Vulnerability Allowing Script Execution in Gogo Shell

Vulnerability

A vulnerability exists in Liferay Portal versions 7.4.3.80 through 7.4.3.132, as well as in Liferay DXP versions 2024.Q1.1 through 2024.Q1.19, 2024.Q2.0 through 2024.Q2.13, 2024.Q3.0 through 2024.Q3.13, 2024.Q4.0 through 2024.Q4.7, and 2025.Q1.0 through 2025.Q1.15. This vulnerability allows attackers to bypass the Captcha verification process and subsequently execute scripts in the Gogo shell.

Impact

Exploitation of this vulnerability could lead to unauthorized script execution in the Gogo shell, potentially allowing attackers to execute arbitrary commands or scripts in the application environment.

Remediation

Users can upgrade to Liferay Portal's master branch or Liferay DXP 2025.Q2.0 to address this vulnerability.

Added: Aug 4, 2025, 10:29 PM
Updated: Aug 4, 2025, 10:29 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
4.8
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.