Liferay Portal
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*
- >= 7.4.0, <= 7.4.3.111
- ~7.4
- ~7.3
A vulnerability exists in Liferay Portal versions 7.4.0 to 7.4.3.111, older unsupported versions, and Liferay DXP versions 2023.Q4.0, 2023.Q3.1 to 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions. This vulnerability allows remote users to access and edit content via the API, as the platforms do not restrict API access before a user has changed their initial password.
Exploitation of this vulnerability allows unauthorized access to APIs, enabling remote users to access and modify content through the API.
Users can upgrade to Liferay Portal 7.4.3.112 or Liferay DXP versions 2024.Q1.1, 2023.Q4.1, 2023.Q3.5, or 7.3 U36 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.