CVE-2022-39975

The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before update 35 does not check user permission before showing the preview of a "Content Page" type page, allowing attackers to view unpublished "Content Page" pages via URL manipulation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
VendorProductVersion
liferaydxp
7.3
liferaydxp
7.3:update_1
liferaydxp
7.3:update_2
liferaydxp
7.3:update_3
liferaydxp
7.3:update_4
liferaydxp
7.3:update_5
liferaydxp
7.3:update_6
liferaydxp
7.3:update_7
liferaydxp
7.3:update_8
liferaydxp
7.3:update_9
liferaydxp
7.4:update_1
liferaydxp
7.4:update_10
liferaydxp
7.4:update_11
liferaydxp
7.4:update_12
liferaydxp
7.4:update_13
liferaydxp
7.4:update_14
liferaydxp
7.4:update_15
liferaydxp
7.4:update_16
liferaydxp
7.4:update_17
liferaydxp
7.4:update_18
liferaydxp
7.4:update_19
liferaydxp
7.4:update_2
liferaydxp
7.4:update_20
liferaydxp
7.4:update_21
liferaydxp
7.4:update_22
liferaydxp
7.4:update_23
liferaydxp
7.4:update_24
liferaydxp
7.4:update_25
liferaydxp
7.4:update_26
liferaydxp
7.4:update_27
liferaydxp
7.4:update_28
liferaydxp
7.4:update_29
liferaydxp
7.4:update_3
liferaydxp
7.4:update_30
liferaydxp
7.4:update_31
liferaydxp
7.4:update_32
liferaydxp
7.4:update_33
liferaydxp
7.4:update_34
liferaydxp
7.4:update_4
liferaydxp
7.4:update_5
liferaydxp
7.4:update_6
liferaydxp
7.4:update_7
liferaydxp
7.4:update_8
liferaydxp
7.4:update_9
liferayliferay_portal
7.3.3 ≤
𝑥
< 7.4.3.35
𝑥
= Vulnerable software versions