Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
liferay-ga4-rce-research — Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known CVE. Agentic loop-hunt: 25 generators, 22 judges, 9 live validators on Docker. Evidence trail + one-go checker included. | Kitploit
Tools/GitHubGitHub/dinosn/liferay-ga4-rce-research
Dynamic Analysis (Sandboxing)Vulnerability AnalysisExploitationScripting & AutomationWeb Application ExploitationWeb SecurityPenetration TestingPapers & Research

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Red Teaming
GitHubdinosn/liferay-ga4-rce-research

liferay-ga4-rce-research

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known CVE. Agentic loop-hunt: 25 generators, 22 judges, 9 live validators on Docker. Evidence trail + one-go checker included.

View Repository
6192 months agoNot yet reviewed
Share

Liferay CE 7.0.3 GA4 — Vulnerability Research (RAPTOR Loop-Hunt)

A security audit of Liferay Portal CE 7.0.3 GA4 (git tag 7.0.3-ga4, commit b2d7cc68a) performed with the RAPTOR loop-hunt methodology: deterministic recon → 25 isolated generator agents reading raw source → 22 independent judge agents refuting from raw → 9 live validators attacking a real GA4 instance in Docker.

Headline: unauthenticated RCE as root reproduced end-to-end (CVE-2020-7961 class), plus 8 more live-verified vulnerabilities — several of them with no known CVE.

⚠️ Legal/ethical: everything here targets a self-hosted test instance. Liferay CE 7.0 is end-of-life (last release 7.0.6 GA7, 2018); these issues are unpatched upstream. Use this material only against systems you own or are explicitly authorized to test.


You are probably looking for https://github.com/dinosn/liferay-ga4-rce-research/blob/main/tools/liferay_ga4_check.py :)

Findings at a glance

Status: ✅ live-verified against the Docker GA4 instance · 🔬 confirmed-by-code (independent judge re-derived the full trace from raw source) · 🧪 needs/config-gated.

IDFindingSeverityAuthStatusEvidence
F-1JSONWS type-override → arbitrary class instantiation + setters → RCE as root (c3p0 HexAsciiSerializedMap → ObjectInputStream → AspectJWeaver file-write → JSP)Criticalnone✅verified/f1-jsonws-deser-rce.md
F-2/poller/* jabsorb javaClass hint → arbitrary class instantiation + field injection, before userId validationHigh (potential)any account (self-registration default-on)✅ sink / RCE arm openverified/F-2-poller.md
F-4XML-RPC pingback.ping fetch-before-validate → blind SSRF + internal port oracle (reached Gogo shell on 127.0.0.1:11311)Mediumnone✅verified/f4-xmlrpc-pingback-ssrf.md
F-5SyncDownloadServlet versionId IDOR → read any DL file version (cross-site, no VIEW check on the streamed object)Highnone (via guest-viewable "leg")✅verified/F-5.md
F-6XSL template engine ignores sandboxing (secureProcessing=false, restricted dropped) → document() SSRF and XSLTC rt:exec command executionCriticalsite template author✅verified/F-6-F-7-template-engines.md
F-7Velocity and FreeMarker restricted templates expose raw propsUtil / saxReaderUtil → portal property + file:// disclosure to guestsHightemplate author✅verified/F-6-F-7-template-engines.md
F-8Image_ table IDOR via /image/*?img_id=N — no token, prefix-scoped checks bypassed by prefix swap, sequential ids enumerableMediumnone✅verified/f-8-image-idor.md
F-11SimpleCaptcha = 4-digit PIN, never invalidated on wrong guesses, guest counter never increments → ~5k-request breakMediumnone✅verified/f11-f12-captcha-reminder.md
F-12Forgot-password: user enumeration + reminder-answer oracle without captcha (fresh-session bypass); empty answer fires a real reset ticket for query-less accountsMedium-Highnone✅verified/f11-f12-captcha-reminder.md
F-13Web Content Display request-param override (groupId/articleId/ddmTemplateKey) → cross-site read of non-guest articles (journal.article.view.permission.check.enabled=false default)Highnone (needs a WCD on a guest page)✅verified/F-13-wcd-param-override.md
F-3OSGi axis-extender skips ServiceAccessPolicy / remote-access marking on module SOAP servicesMedium (High w/ WSDD module)none🔬judge/axis-spring-remoting.md
F-9OpenID links victim account to attacker's OpenID before assertion verification → account takeoverHighnone (OpenID enabled, non-default)🔬 🧪judge/sso-autologin.md
F-10TunnelServlet readObject guarded only by a class blacklist; ROME/JdbcRowSetImpl/c3p0/AspectJWeaver gadgets on classpathCritical potentialtrusted peer (shared secret + allowed host)✅ barriers hold pre-authverified/f10-f20-tunnel-auth-pipeline.md
F-14TokenAutoLogin trusts a bare SM_USER header (no verification, no IP allowlist)Mediumnone (token SSO enabled, non-default)🔬 🧪judge/sso-autologin.md
F-15Site-admin LAR import smuggles RolesAdminPortletDataHandler → mass company-role deletion / permission wipeMediumsite admin🔬judge/export-import-lar.md
F-16OpenSocial (not in default bundle): pre-auth makeRequest SSRF, /gadgets/ifr origin JS, forgeable security tokens → impersonation, stored XSSHigh ×4none / site member🔬 (deployment-conditional)judge/opensocial-shindig.md
F-17WSRP (not in default bundle): pre-auth ProxyServlet SSRF; markup endpoint → arbitrary portlet render + layout typeSettings persistenceMediumnone🔬 (deployment-conditional)judge/wsrp.md

Full curated list with rejections: FINDINGS.md · narrative report: REPORT.md


New vs. known — CVE comparison

Catalogue of ~50 known Liferay 7.0.x issues used as prior art: PRIOR-ART.md (OSV [email protected], NVD sweep, Code White / CERT-EU advisories).

Download Tool