QID 731010
Date Published: 2023-12-26
QID 731010: Liferay Portal Unauthorized Access Vulnerability
The Dynamic Data Mapping module in Liferay Portal does not limit Document and Media files which can be downloaded from a Form, which allows remote attackers to download any file from Document and Media via a crafted URL.
Affected Versions:
Liferay Portal 7.4.3.67
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Liferay Portal in response banner.
Successful exploit may allow remote attackers to download any file from Document and Media via a crafted URL.
Solution
Vendor has released patch. For more info, please refer to Liferay Portal Security Advisory
Vendor References
CVEs related to QID 731010
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-33948 |
|