QID 731191
Date Published: 2024-02-22
QID 731191: Liferay Portal Man-in-the-Middle (MITM) Attack Vulnerability (CVE-2024-26270)
Liferay Portal is an open-source enterprise web platform for building business solutions and collaborative applications.
CVE-2024-26270: The Account Settings page in Liferay Portal embeds the users hashed password in the HTML page source, which allows man-in-the-middle attackers to steal a users hashed password.
Affected Versions:
Liferay Portal from version 7.4.3.76 to 7.4.3.99.
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of Liferay Portal in the response banner.
Successful exploitation of this vulnerability allows man-in-the-middle attackers to steal a users hashed password.
Solution
Vendor has released patch. For more info, please refer to Liferay Portal Security Advisory
Vendor References
CVEs related to QID 731191
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Liferay Portal |
|