CVE-2022-38512Missing Authorization in Portal

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 55.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 22
Latest updateSep 23

Description

The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDliferay/liferay_portal7.4.3.127.4.3.36
NVDliferay/dxp7.4

🔴Vulnerability Details

3
GHSA
Liferay Portal and Liferay DXP Fails to Check Permissions in Translation Module2022-09-23
OSV
Liferay Portal and Liferay DXP Fails to Check Permissions in Translation Module2022-09-23
CVEList
CVE-2022-38512: The Translation module in Liferay Portal v72022-09-22
CVE-2022-38512 — Missing Authorization in Portal | cvebase