The organization selector in Liferay Portal 7.4.3.81...
Moderate severity
Unreviewed
Published
Aug 2, 2023
to the GitHub Advisory Database
•
Updated Oct 2, 2024
Description
Published by the National Vulnerability Database
Aug 2, 2023
Published to the GitHub Advisory Database
Aug 2, 2023
Last updated
Oct 2, 2024
The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.
References