Liferay Portal and Liferay DXP Organization Selector Permission Vulnerability

Vulnerability

A vulnerability exists in the organization selector of Liferay Portal versions 7.4.0 to 7.4.3.124, as well as in Liferay DXP versions 2024.Q1.1 to 2024.Q1.12 and 7.4 updates 81 to 85. This vulnerability arises because the organization selector does not properly verify user permissions, allowing remote authenticated users to access a complete list of organizations.

Impact

Exploitation of this vulnerability leads to unauthorized access to organization names, allowing users to view all organizations without proper permissions.

Remediation

Users can upgrade to Liferay Portal 7.4.3.125, Liferay DXP 2024.Q1.13, Liferay DXP 2024.Q2.1, or Liferay DXP 2024.Q3.0.

Added: Sep 12, 2025, 3:17 AM
Updated: Sep 12, 2025, 3:17 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
5.2
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.