CVE-2022-26595
19.04.2022, 13:15
Liferay Portal 7.3.7, 7.4.0, and 7.4.1, and Liferay DXP 7.2 fix pack 13, and 7.3 fix pack 2 does not properly check user permission when accessing a list of sites/groups, which allows remote authenticated users to view sites/groups via the user's site membership assignment UI.Enginsight
Vendor | Product | Version |
---|---|---|
liferay | digital_experience_platform | 7.2:fix_pack_13 |
liferay | digital_experience_platform | 7.3:fix_pack_2 |
liferay | liferay_portal | 7.3.7 |
liferay | liferay_portal | 7.4.0 |
liferay | liferay_portal | 7.4.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References