CVE-2022-38512
22.09.2022, 01:15
The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.Enginsight
Vendor | Product | Version |
---|---|---|
liferay | dxp | 7.4:update_10 |
liferay | dxp | 7.4:update_11 |
liferay | dxp | 7.4:update_12 |
liferay | dxp | 7.4:update_13 |
liferay | dxp | 7.4:update_14 |
liferay | dxp | 7.4:update_15 |
liferay | dxp | 7.4:update_16 |
liferay | dxp | 7.4:update_17 |
liferay | dxp | 7.4:update_18 |
liferay | dxp | 7.4:update_19 |
liferay | dxp | 7.4:update_20 |
liferay | dxp | 7.4:update_21 |
liferay | dxp | 7.4:update_22 |
liferay | dxp | 7.4:update_23 |
liferay | dxp | 7.4:update_24 |
liferay | dxp | 7.4:update_25 |
liferay | dxp | 7.4:update_26 |
liferay | dxp | 7.4:update_27 |
liferay | dxp | 7.4:update_28 |
liferay | dxp | 7.4:update_29 |
liferay | dxp | 7.4:update_3 |
liferay | dxp | 7.4:update_30 |
liferay | dxp | 7.4:update_31 |
liferay | dxp | 7.4:update_32 |
liferay | dxp | 7.4:update_33 |
liferay | dxp | 7.4:update_34 |
liferay | dxp | 7.4:update_35 |
liferay | dxp | 7.4:update_36 |
liferay | dxp | 7.4:update_8 |
liferay | dxp | 7.4:update_9 |
liferay | liferay_portal | 7.4.3.12 ≤ 𝑥 ≤ 7.4.3.36 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration