Логотип exploitDog
bind:CVE-2021-33330
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-33330

Количество 2

Количество 2

nvd логотип

CVE-2021-33330

больше 4 лет назад

Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharing (CORS) protected resources if the user is only authenticated using the portal session authentication, which allows remote attackers to obtain sensitive information including the targeted user’s email address and current CSRF token.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-6xxc-4jc4-7jv3

больше 3 лет назад

Exposure of Resource to Wrong Sphere in Liferay Portal

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-33330

Liferay Portal 7.2.0 through 7.3.2, and Liferay DXP 7.2 before fix pack 9, allows access to Cross-origin resource sharing (CORS) protected resources if the user is only authenticated using the portal session authentication, which allows remote attackers to obtain sensitive information including the targeted user’s email address and current CSRF token.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-6xxc-4jc4-7jv3

Exposure of Resource to Wrong Sphere in Liferay Portal

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу