liferay.md (7696B)
1 --- 2 title: "Liferay" 3 section: "Cheatsheets" 4 sectionSlug: "cheatsheets" 5 sourcePath: "docs/cheatsheets/liferay.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cheatsheets/liferay.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Liferay 12 13 > Liferay Portal is an open-source enterprise portal platform used for building web applications and digital experiences. It provides features like content management, user authentication, collaboration tools, and customizable dashboards. - [liferay/liferay-portal](https://github.com/liferay/liferay-portal) 14 15 ## Summary 16 17 * [Portlets](#portlets) 18 * [Login Page](#login-page) 19 * [Register Page](#register-page) 20 * [User Profile](#user-configuration) 21 * [User Configuration](#user-configuration) 22 * [Control Panel](#control-panel) 23 * [API](#api) 24 * [Vulnerabilities](#vulnerabilities) 25 * [Open Redirect](#open-redirect) 26 * [Code Execution on Administrator Control Panel](#code-execution-on-administrator-control-panel) 27 * [Resource Leakage Through I18nServlet](#resource-leakage-through-i18nservlet) 28 * [Remote Code Execution via JSON web services](#remote-code-execution-via-json-web-services) 29 * [References](#references) 30 31 ## Portlets 32 33 ```ps1 34 /?p_p_id=<portlet_ID>&p_p_lifecycle=0&p_p_state=<window_state>&p_p_mode=<mode> 35 ``` 36 37 * **portlet_ID**: ID of the portlet to be executed. Can be a numeric ID, which is an incremental number for each portlet, or a [liferay.com/Fully-Qualified-Portlet-IDs](https://help.liferay.com/hc/en-us/articles/360018511712-Fully-Qualified-Portlet-IDs), which is a string. 38 39 * **window_state**: Amount of space a portlet takes up on a page. Values are: normal, maximized 40 minimized 41 42 * **mode**: Portlet's current function. Values are: view, edit, help 43 44 | Name | Portlet ID | 45 | ------------------- | ----------------------------------------------------------------------------- | 46 | Asset Publisher | com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet | 47 | Documents and Media | com_liferay_document_library_web_portlet_DLPortlet | 48 | Navigation Menu | com_liferay_site_navigation_menu_web_portlet_SiteNavigationMenuPortlet | 49 | Site Map | com_liferay_site_navigation_site_map_web_portlet_SiteNavigationSiteMapPortlet | 50 | Web Content Display | com_liferay_journal_content_web_portlet_JournalContentPortlet | 51 | Search Bar | com_liferay_portal_search_web_search_bar_portlet_SearchBarPortlet | 52 | Search | com_liferay_portal_search_web_portlet_SearchPortlet | 53 54 ## Login Page 55 56 ```ps1 57 /login 58 /c/portal/login 59 /?p_p_id=58&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view 60 /?p_p_id=58&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view&saveLastPath=false&_58_struts_action=%2Flogin%2Flogin 61 /?p_p_id=com_liferay_login_web_portlet_LoginPortlet&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view 62 /?p_p_id=com_liferay_login_web_portlet_LoginPortlet&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view&saveLastPath=false&_58_struts_action=%2Flogin%2Flogin 63 ``` 64 65 ## Register Page 66 67 ```ps1 68 /?p_p_id=58&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view&_com_liferay_login_web_portlet_LoginPortlet_mvcRenderCommandName=%2Flogin%2Fcreate_account 69 /?p_p_id=58&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view&saveLastPath=false&_58_struts_action=%2Flogin%2Flogin&_com_liferay_login_web_portlet_LoginPortlet_mvcRenderCommandName=%2Flogin%2Fcreate_account 70 /?p_p_id=com_liferay_login_web_portlet_LoginPortlet&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view&_com_liferay_login_web_portlet_LoginPortlet_mvcRenderCommandName=%2Flogin%2Fcreate_account 71 /?p_p_id=com_liferay_login_web_portlet_LoginPortlet&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view&saveLastPath=false&_58_struts_action=%2Flogin%2Flogin&_com_liferay_login_web_portlet_LoginPortlet_mvcRenderCommandName=%2Flogin%2Fcreate_account 72 ``` 73 74 ## User Profile 75 76 ```ps1 77 /web/<user> 78 /web/<user>/home 79 /user/<other_user>/control_panel/manage 80 /user/<other_user>/~/control_panel/manage 81 /web/guest 82 /web/guest/home 83 ``` 84 85 ## User Configuration 86 87 ```ps1 88 /user/<user> 89 /user/<user>/manage 90 /user/<user>/manage?p_p_id=com_liferay_my_account_web_portlet_MyAccountPortlet&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view 91 /group/control_panel/manage?p_p_id=com_liferay_my_account_web_portlet_MyAccountPo 92 ``` 93 94 ## Control Panel 95 96 Endpoints reachable by authenticated users. 97 98 ```ps1 99 /group/control_panel/manage 100 /group/guest/control_panel/manage 101 /group/guest/~/control_panel/manage 102 /group/<user>/control_panel/manage 103 /group/<user>/~/control_panel/manage 104 /user/<user>/control_panel/manage 105 /user/<user>/~/control_panel/manage 106 ``` 107 108 ## API 109 110 * [nuclei-templates/http/misconfiguration/liferay/liferay-axis.yaml](https://github.com/projectdiscovery/nuclei-templates/blob/main/http/misconfiguration/liferay/liferay-axis.yaml) 111 * [nuclei-templates/http/misconfiguration/liferay/liferay-jsonws.yaml](https://github.com/projectdiscovery/nuclei-templates/blob/main/http/misconfiguration/liferay/liferay-jsonws.yaml) 112 * [nuclei-templates/http/misconfiguration/liferay/liferay-api.yaml](https://github.com/projectdiscovery/nuclei-templates/blob/main/http/misconfiguration/liferay/liferay-api.yaml) 113 114 | Name | Path | 115 | ----------------- | ------------- | 116 | JSON Web Services | `/api/jsonws` | 117 | SOAP | `/api/axis` | 118 | GraphQL | `/o/graphql` | 119 | JSON and GraphQL | `/o/api` | 120 121 ## Vulnerabilities 122 123 * [liferay.dev/known-vulnerabilities](https://liferay.dev/portal/security/known-vulnerabilities) 124 * [ilmila/J2EEScan](https://github.com/ilmila/J2EEScan/blob/master/src/main/java/burp/j2ee/issues/impl/LiferayAPI.java) 125 126 ### Open Redirect 127 128 ```ps1 129 /html/common/referer_jsp.jsp?referer=<url> 130 /html/common/referer_js.jsp?referer=<url> 131 /html/common/forward_jsp.jsp?FORWARD_URL=<url> 132 /html/common/forward_js.jsp?FORWARD_URL=<url> 133 ``` 134 135 ### Code Execution on Administrator Control Panel 136 137 Gogo shell, read files 138 139 ```ps1 140 /group/control_panel/manage?p_p_id=com_liferay_gogo_shell_web_internal_portlet_GogoShellPortlet&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view&_com_liferay_gogo_shell_web_internal_portlet_GogoShellPortlet_javax.portlet.action=executeCommand 141 ``` 142 143 Groovy Interpreter 144 145 ```ps1 146 /group/control_panel/manage?p_p_id=com_liferay_server_admin_web_portlet_ServerAdminPortlet&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view&_com_liferay_server_admin_web_portlet_ServerAdminPortlet_mvcRenderCommandName=%2Fserver_admin%2Fview&_com_liferay_server_admin_web_portlet_ServerAdminPortlet_tabs1=script 147 ``` 148 149 ### Resource Leakage Through I18nServlet 150 151 Liferay is vulnerable to local file inclusion in the I18n Servlet because it leaks information via sending an HTTP request to /[language]/[resource];.js (also .jsp works). [nuclei-templates/http/vulnerabilities/j2ee/liferay-resource-leak.yaml](https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/j2ee/liferay-resource-leak.yaml) 152 153 * Liferay Portal 7.3.0 GA1 154 * Liferay Portal 7.0.2 GA3 155 156 ### Remote Code Execution via JSON web services 157 158 * [nuclei-templates/http/cves/2020/CVE-2020-7961.yaml](https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-7961.yaml) 159 160 ## References 161 162 * [Pentesting Liferay Applications - Víctor Fresco - February 6, 2025](https://www.tarlogic.com/blog/pentesting-liferay-applications/) 163 * [How to exploit Liferay CVE-2020-7961 : quick journey to PoC - Thomas Etrillard - March 30, 2020](https://www.synacktiv.com/en/publications/how-to-exploit-liferay-cve-2020-7961-quick-journey-to-poc.html)