Liferay Portal
cpe:2.3:a:liferay:liferay_portal:*:*:*:*:*:*:*
- >= 7.1.0, <= 7.4.3.111
An Insecure Direct Object Reference (IDOR) vulnerability has been identified in Liferay Portal versions 7.4.0 through 7.4.3.111, older unsupported versions, and Liferay DXP versions 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92. This vulnerability allows remote authenticated users in one virtual instance to assign an organization to a user in a different virtual instance by using the _com_liferay_users_admin_web_portlet_UsersAdminPortlet_addUserIds parameter.
Exploitation of this vulnerability allows for unauthorized cross-instance organization assignments, potentially leading to privilege escalation or unauthorized access to resources.
Users can upgrade to Liferay Portal 7.4.3.112 or Liferay DXP versions 2024.Q1.1 or 2023.Q4.6 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.