Логотип exploitDog
bind:CVE-2025-43788
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-43788

Количество 2

Количество 2

nvd логотип

CVE-2025-43788

5 месяцев назад

The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.4 update 81 through update 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-v53g-736w-mgw4

5 месяцев назад

Liferay Portal's Organization Selector exposes organization data to remote authenticated users

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-43788

The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.4 update 81 through update 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.

CVSS3: 4.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-v53g-736w-mgw4

Liferay Portal's Organization Selector exposes organization data to remote authenticated users

0%
Низкий
5 месяцев назад

Уязвимостей на страницу