CVE-2023-3426

Description

The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.

Risk Information

Base Score
4.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.324

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2023-3426 are affected in Liferay - release.dxp.bom 7.4.143Windows
Vulnerabilities CVE-2023-3426 are fixed in Liferay - com.liferay.organizations.item.selector.web 4.0.14Windows
Vulnerabilities CVE-2023-3426 are affected in Liferay - release.dxp.bom for Linux 7.4.143Linux
Vulnerabilities CVE-2023-3426 are fixed in Liferay - com.liferay.organizations.item.selector.web for Linux 4.0.14Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234