CVE-2014-3416
EUVD-2014-342929.05.2014, 14:19
uPortal before 4.0.13.1 does not properly check the MANAGE permissions, which allows remote authenticated users to manage arbitrary portlets by leveraging the SUBSCRIBE permission for the portlet-admin portlet.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jasig | uportal | 𝑥 ≤ 4.0.13 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration