Liferay Portal
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*
- >= 7.2.0, <= 7.4.3.117
An Insecure Direct Object Reference (IDOR) vulnerability has been identified in Liferay Portal versions 7.4.0 through 7.4.3.117, as well as in several Liferay DXP versions. This vulnerability allows remote authenticated users to access audit events from different virtual instances by manipulating the '_com_liferay_portal_security_audit_web_portlet_AuditPortlet_auditEventId' parameter.
Exploitation of this vulnerability allows for unauthorized access to audit events from different virtual instances, potentially leading to information disclosure.
Users can upgrade to Liferay Portal 7.4.3.118 or Liferay DXP 2024.Q1.6 or 2024.Q2.0 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.