Логотип exploitDog
bind:CVE-2025-43732
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-43732

Количество 2

Количество 2

nvd логотип

CVE-2025-43732

6 месяцев назад

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.17 and 7.4 GA through update 92 is vulnerable to Insecure Direct Object Reference (IDOR) in the groupId parameter of the _com_liferay_roles_selector_web_portlet_RolesSelectorPortlet_groupId. When an organization administrator modifies this parameter id value, they can gain unauthorized access to user lists from other organizations.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-v6xr-v2qg-h22h

6 месяцев назад

Liferay Portal Vulnerable to Insecure Direct Object Reference

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-43732

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.10, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.17 and 7.4 GA through update 92 is vulnerable to Insecure Direct Object Reference (IDOR) in the groupId parameter of the _com_liferay_roles_selector_web_portlet_RolesSelectorPortlet_groupId. When an organization administrator modifies this parameter id value, they can gain unauthorized access to user lists from other organizations.

CVSS3: 2.7
0%
Низкий
6 месяцев назад
github логотип
GHSA-v6xr-v2qg-h22h

Liferay Portal Vulnerable to Insecure Direct Object Reference

0%
Низкий
6 месяцев назад

Уязвимостей на страницу