CVE-2014-3417
29.05.2014, 14:19
uPortal before 4.0.13.1 does not properly check the CONFIG permission, which allows remote authenticated users to configure portlets by leveraging the SUBSCRIBE permission for a portlet.Enginsight
Vendor | Product | Version |
---|---|---|
jasig | uportal | 𝑥 ≤ 4.0.13 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration