Liferay Portal
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*
- >= 7.4.3.94, <= 7.4.3.124
- >= 7.4.3.81, <= 7.4.3.85
A vulnerability exists in the organization selector of Liferay Portal versions 7.4.0 to 7.4.3.124, as well as in Liferay DXP versions 2024.Q1.1 to 2024.Q1.12 and 7.4 updates 81 to 85. This vulnerability arises because the organization selector does not properly verify user permissions, allowing remote authenticated users to access a complete list of organizations.
Exploitation of this vulnerability leads to unauthorized access to organization names, allowing users to view all organizations without proper permissions.
Users can upgrade to Liferay Portal 7.4.3.125, Liferay DXP 2024.Q1.13, Liferay DXP 2024.Q2.1, or Liferay DXP 2024.Q3.0.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.