← Back

CVE-2023-33949

nvd nist
Published: May 24, 2023Modified: Jan 9, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property `company.security.strangers.verify` should be set to true.

Affected (5)

2 products
Digital Experience Platform
Liferay Portal
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
From 7.0 to 7.2
Liferay
From 7.0.0 to 7.0.6
From 7.1.0 to 7.1.3
From 7.2.0 to 7.2.1
Version 7.3.0

Timeline

No history available yet.