QID 731023
Date Published: 2023-12-26
QID 731023: Liferay Portal Unauthorized View Access Vulnerability
The organization selector in Liferay Portal does not check user permission, which allows remote authenticated users to obtain a list of all organizations.
Affected Versions:
Liferay Portal 7.4.3.81 - 7.4.3.85
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable version of Liferay Portal in response banner.
Successful exploit may allow remote authenticated users to obtain a list of all organizations.
Solution
Vendor has released patch. For more info, please refer to Liferay Portal Security Advisory
Vendor References
CVEs related to QID 731023
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-3426 |
|