← Back

CVE-2023-3426

nvd nist
Published: Aug 2, 2023Modified: Jan 30, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.

Affected (6)

2 products
Digital Experience Platform
Liferay Portal
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Liferay
Version 7.4 update81
Version 7.4 update82
Version 7.4 update83
Version 7.4 update84
Version 7.4 update85
From 7.4.3.81 to 7.4.3.85

Timeline

No history available yet.