CVE-2020-15839: Liferay Digital Experience Platform

Medium severity, CVSS 6.5. EPSS: 2.2% chance of exploitation in the next 30 days.

Liferay Portal before 7.3.3, and Liferay DXP 7.1 before fix pack 18 and 7.2 before fix pack 6, does not restrict the size of a multipart/form-data POST action, which allows remote authenticated users to conduct denial-of-service attacks by uploading large files.

Affected products

  • Liferay Digital Experience Platform: version 7.1 only; version 7.2 only
  • Liferay Liferay Portal: before 7.3.3 (fixed in 7.3.3)

Published 2020-09-22. Last modified 2026-06-17.