Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-chr3-w547-85hw

Опубликовано: 19 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Liferay Portal Commerce component has Incorrect Permission Assignment for Critical Resource

The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and 7.3 Service Pack 3 through update 35 saves virtual products uploaded to Documents and Media with guest view permission, which allows remote attackers to access and download virtual products for free via a crafted URL.

Пакеты

Наименование

com.liferay.commerce:com.liferay.commerce.product.type.virtual.service

maven
Затронутые версииВерсия исправления

< 4.0.47

4.0.47

EPSS

Процентиль: 4%
0.0002
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 5.3
nvd
5 месяцев назад

The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and 7.3 service pack 3 through update 35 saves virtual products uploaded to Documents and Media with guest view permission, which allows remote attackers to access and download virtual products for free via a crafted URL.

EPSS

Процентиль: 4%
0.0002
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-732