Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.
PoC: CVE-2020-7961-Mass
CVE-2020–7961 Mass exploit for Script Kiddies
PoC: CVE-2020-7961
Exploit script for CVE-2020-7961
PoC: CVE-2020-7961-payloads
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS)
PoC: POC-CVE-2020-7961-Token-iterate
POC-CVE-2020-7961-Token-iterate
PoC: GLiferay-CVE-2020-7961-golang
Detect vulns liferay CVE-2020-7961 by Nattroc (EOG Team)
PoC: liferay-ga4-rce-research
Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known CVE. Agentic loop-hunt: 25 generators, 22 judges, 9 live validators on Docker. Evidence trail + one-go checker included.
PoC: GLiferay-CVE-2020-7961-golang
Detect vulns liferay CVE-2020-7961 by Nattroc (EOG Team)
PoC: POC-CVE-2020-7961-Token-iterate
POC-CVE-2020-7961-Token-iterate
PoC: CVE-2020-7961-Mass
CVE-2020–7961 Mass exploit for Script Kiddies
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free