daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

liferay.md (7696B)


      1 ---
      2 title: "Liferay"
      3 section: "Cheatsheets"
      4 sectionSlug: "cheatsheets"
      5 sourcePath: "docs/cheatsheets/liferay.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cheatsheets/liferay.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Liferay
     12 
     13 > Liferay Portal is an open-source enterprise portal platform used for building web applications and digital experiences. It provides features like content management, user authentication, collaboration tools, and customizable dashboards. - [liferay/liferay-portal](https://github.com/liferay/liferay-portal)
     14 
     15 ## Summary
     16 
     17 * [Portlets](#portlets)
     18 * [Login Page](#login-page)
     19 * [Register Page](#register-page)
     20 * [User Profile](#user-configuration)
     21 * [User Configuration](#user-configuration)
     22 * [Control Panel](#control-panel)
     23 * [API](#api)
     24 * [Vulnerabilities](#vulnerabilities)
     25     * [Open Redirect](#open-redirect)
     26     * [Code Execution on Administrator Control Panel](#code-execution-on-administrator-control-panel)
     27     * [Resource Leakage Through I18nServlet](#resource-leakage-through-i18nservlet)
     28     * [Remote Code Execution via JSON web services](#remote-code-execution-via-json-web-services)
     29 * [References](#references)
     30 
     31 ## Portlets
     32 
     33 ```ps1
     34 /?p_p_id=<portlet_ID>&p_p_lifecycle=0&p_p_state=<window_state>&p_p_mode=<mode>
     35 ```
     36 
     37 * **portlet_ID**: ID of the portlet to be executed. Can be a numeric ID, which is an incremental number for each portlet, or a [liferay.com/Fully-Qualified-Portlet-IDs](https://help.liferay.com/hc/en-us/articles/360018511712-Fully-Qualified-Portlet-IDs), which is a string.
     38 
     39 * **window_state**: Amount of space a portlet takes up on a page. Values are: normal, maximized
     40 minimized
     41 
     42 * **mode**: Portlet's current function. Values are: view, edit, help
     43 
     44 | Name                | Portlet ID                                                                    |
     45 | ------------------- | ----------------------------------------------------------------------------- |
     46 | Asset Publisher     | com_liferay_asset_publisher_web_portlet_AssetPublisherPortlet                 |
     47 | Documents and Media | com_liferay_document_library_web_portlet_DLPortlet                            |
     48 | Navigation Menu     | com_liferay_site_navigation_menu_web_portlet_SiteNavigationMenuPortlet        |
     49 | Site Map            | com_liferay_site_navigation_site_map_web_portlet_SiteNavigationSiteMapPortlet |
     50 | Web Content Display | com_liferay_journal_content_web_portlet_JournalContentPortlet                 |
     51 | Search Bar          | com_liferay_portal_search_web_search_bar_portlet_SearchBarPortlet             |
     52 | Search              | com_liferay_portal_search_web_portlet_SearchPortlet                           |
     53 
     54 ## Login Page
     55 
     56 ```ps1
     57 /login
     58 /c/portal/login
     59 /?p_p_id=58&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view
     60 /?p_p_id=58&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view&saveLastPath=false&_58_struts_action=%2Flogin%2Flogin
     61 /?p_p_id=com_liferay_login_web_portlet_LoginPortlet&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view
     62 /?p_p_id=com_liferay_login_web_portlet_LoginPortlet&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view&saveLastPath=false&_58_struts_action=%2Flogin%2Flogin
     63 ```
     64 
     65 ## Register Page
     66 
     67 ```ps1
     68 /?p_p_id=58&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view&_com_liferay_login_web_portlet_LoginPortlet_mvcRenderCommandName=%2Flogin%2Fcreate_account
     69 /?p_p_id=58&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view&saveLastPath=false&_58_struts_action=%2Flogin%2Flogin&_com_liferay_login_web_portlet_LoginPortlet_mvcRenderCommandName=%2Flogin%2Fcreate_account
     70 /?p_p_id=com_liferay_login_web_portlet_LoginPortlet&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view&_com_liferay_login_web_portlet_LoginPortlet_mvcRenderCommandName=%2Flogin%2Fcreate_account
     71 /?p_p_id=com_liferay_login_web_portlet_LoginPortlet&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view&saveLastPath=false&_58_struts_action=%2Flogin%2Flogin&_com_liferay_login_web_portlet_LoginPortlet_mvcRenderCommandName=%2Flogin%2Fcreate_account
     72 ```
     73 
     74 ## User Profile
     75 
     76 ```ps1
     77 /web/<user>
     78 /web/<user>/home
     79 /user/<other_user>/control_panel/manage
     80 /user/<other_user>/~/control_panel/manage
     81 /web/guest
     82 /web/guest/home
     83 ```
     84 
     85 ## User Configuration
     86 
     87 ```ps1
     88 /user/<user>
     89 /user/<user>/manage
     90 /user/<user>/manage?p_p_id=com_liferay_my_account_web_portlet_MyAccountPortlet&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view
     91 /group/control_panel/manage?p_p_id=com_liferay_my_account_web_portlet_MyAccountPo
     92 ```
     93 
     94 ## Control Panel
     95 
     96 Endpoints reachable by authenticated users.
     97 
     98 ```ps1
     99 /group/control_panel/manage
    100 /group/guest/control_panel/manage
    101 /group/guest/~/control_panel/manage
    102 /group/<user>/control_panel/manage
    103 /group/<user>/~/control_panel/manage
    104 /user/<user>/control_panel/manage
    105 /user/<user>/~/control_panel/manage
    106 ```
    107 
    108 ## API
    109 
    110 * [nuclei-templates/http/misconfiguration/liferay/liferay-axis.yaml](https://github.com/projectdiscovery/nuclei-templates/blob/main/http/misconfiguration/liferay/liferay-axis.yaml)
    111 * [nuclei-templates/http/misconfiguration/liferay/liferay-jsonws.yaml](https://github.com/projectdiscovery/nuclei-templates/blob/main/http/misconfiguration/liferay/liferay-jsonws.yaml)
    112 * [nuclei-templates/http/misconfiguration/liferay/liferay-api.yaml](https://github.com/projectdiscovery/nuclei-templates/blob/main/http/misconfiguration/liferay/liferay-api.yaml)
    113 
    114 | Name              | Path          |
    115 | ----------------- | ------------- |
    116 | JSON Web Services | `/api/jsonws` |
    117 | SOAP              | `/api/axis`   |
    118 | GraphQL           | `/o/graphql`  |
    119 | JSON and GraphQL  | `/o/api`      |
    120 
    121 ## Vulnerabilities
    122 
    123 * [liferay.dev/known-vulnerabilities](https://liferay.dev/portal/security/known-vulnerabilities)
    124 * [ilmila/J2EEScan](https://github.com/ilmila/J2EEScan/blob/master/src/main/java/burp/j2ee/issues/impl/LiferayAPI.java)
    125 
    126 ### Open Redirect
    127 
    128 ```ps1
    129 /html/common/referer_jsp.jsp?referer=<url>
    130 /html/common/referer_js.jsp?referer=<url>
    131 /html/common/forward_jsp.jsp?FORWARD_URL=<url>
    132 /html/common/forward_js.jsp?FORWARD_URL=<url>
    133 ```
    134 
    135 ### Code Execution on Administrator Control Panel
    136 
    137 Gogo shell, read files
    138 
    139 ```ps1
    140 /group/control_panel/manage?p_p_id=com_liferay_gogo_shell_web_internal_portlet_GogoShellPortlet&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view&_com_liferay_gogo_shell_web_internal_portlet_GogoShellPortlet_javax.portlet.action=executeCommand
    141 ```
    142 
    143 Groovy Interpreter
    144 
    145 ```ps1
    146 /group/control_panel/manage?p_p_id=com_liferay_server_admin_web_portlet_ServerAdminPortlet&p_p_lifecycle=0&p_p_state=maximized&p_p_mode=view&_com_liferay_server_admin_web_portlet_ServerAdminPortlet_mvcRenderCommandName=%2Fserver_admin%2Fview&_com_liferay_server_admin_web_portlet_ServerAdminPortlet_tabs1=script
    147 ```
    148 
    149 ### Resource Leakage Through I18nServlet
    150 
    151 Liferay is vulnerable to local file inclusion in the I18n Servlet because it leaks information via sending an HTTP request to /[language]/[resource];.js (also .jsp works). [nuclei-templates/http/vulnerabilities/j2ee/liferay-resource-leak.yaml](https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/j2ee/liferay-resource-leak.yaml)
    152 
    153 * Liferay Portal 7.3.0 GA1
    154 * Liferay Portal 7.0.2 GA3
    155 
    156 ### Remote Code Execution via JSON web services
    157 
    158 * [nuclei-templates/http/cves/2020/CVE-2020-7961.yaml](https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-7961.yaml)
    159 
    160 ## References
    161 
    162 * [Pentesting Liferay Applications - Víctor Fresco - February 6, 2025](https://www.tarlogic.com/blog/pentesting-liferay-applications/)
    163 * [How to exploit Liferay CVE-2020-7961 : quick journey to PoC - Thomas Etrillard - March 30, 2020](https://www.synacktiv.com/en/publications/how-to-exploit-liferay-cve-2020-7961-quick-journey-to-poc.html)