CVE-2020-7961 | Liferay Portal up to 7.2.1 CE GA1 JSONWS deserialization (ID 157254 / EDB-48332)
A vulnerability classified as critical has been found in Liferay Portal up to 7.2.1 CE GA1. Affected is an unknown function of the component JSONWS. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2020-7961. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.