QID 731146
Date Published: 2024-02-12
QID 731146: Liferay Portal Multiple Security Vulnerabilities (CVE-2024-25146, CVE-2024-25148)
Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.
CVE-2024-25146: Liferay Portal returns with different responses depending on whether a site does not exist or if the user does not have permission to access the site, which allows remote attackers to discover the existence of sites by enumerating URLs.
CVE-2024-25148: In Liferay Portal the `doAsUserId` URL parameter may get leaked when creating linked content using the WYSIWYG editor and while impersonating a user.
Affected Versions:
Liferay Portal 7.2.0 and 7.2.1.
Liferay Portal from version 7.3.0 to 7.3.7.
Liferay Portal 7.4.0 and 7.4.1
Liferay Portal, older unsupported versions.
QID Detection Logic (Unauthenticated): This QID checks for vulnerable versions of Liferay Portal in the response banner.
Successful exploitation of this vulnerability may affect Confidentiality, Integrity, and Availability of data.
- Liferay Portal_CVE-2024-25146 -
liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25146 - Liferay Portal_Liferay Portal -
liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25148
CVEs related to QID 731146
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2024-25148 |
|
||
| CVE-2024-25146 |
|