{"id":"CVE-2019-11444","details":"An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute OS commands. Commands can be executed via a [command].execute() call, as demonstrated by \"def cmd =\" in the ServerAdminPortlet_script value to group/control_panel/manage. Valid credentials for an application administrator user account are required. NOTE: The developer disputes this as a vulnerability since it is a feature for administrators to run groovy scripts and therefore not a design flaw","modified":"2026-09-05T08:10:13.838650Z","published":"2019-04-22T11:29:05.830Z","references":[{"type":"WEB","url":"https://dev.liferay.com/discover/portal/-/knowledge_base/7-1/running-scripts-from-the-script-console"},{"type":"EVIDENCE","url":"https://pentest.com.tr/exploits/Liferay-CE-Portal-Tomcat-7-1-2-ga3-Groovy-Console-Remote-Command-Execution-Metasploit.html"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/46525"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/liferay/liferay-portal","events":[{"introduced":"0ac7dd652f3cac9b7880e6dea92912b2d02dca3a"},{"last_affected":"0ac7dd652f3cac9b7880e6dea92912b2d02dca3a"}],"database_specific":{"cpe":"cpe:2.3:a:liferay:liferay_portal:7.1.2:ga3:*:*:*:*:*:*","extracted_events":[{"introduced":"7.1.2-ga3"},{"last_affected":"7.1.2-ga3"}],"source":"CPE_STRING"}}],"versions":["7.1.2-ga3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11444.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}