QID 731177

Date Published: 2024-02-26

QID 731177: Liferay Portal Multiple Vulnerabilities

Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.

Affected Versions:
Liferay Portal from version 7.4.0 to 7.4.2
Liferay Portal from version 7.3.0 to 7.3.7.
Liferay Portal 7.2.0 and 7.2.1.
Liferay Portal, older unsupported versions.

QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Liferay Portal in the response banner.

Successful exploitation of this vulnerability allows remote authenticated users to obtain a user's full name from the page's title by enumerating user screen names.

  • CVSS V3 rated as Critical - 9 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Vendor has released patch. For more info, please refer to Liferay Portal Security Advisory

    Software Advisories
    Advisory ID Software Component Link
    Liferay Portal Security Advisory URL Logo liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/CVE-2024-25601