CVE-2022-38512
published 2022-09-22CVE-2022-38512: The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user…
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.56%
43.2th percentile
The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
| liferay | dxp | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Liferay Portal and Liferay DXP Fails to Check Permissions in Translation Module
ghsa·2022-09-23
CVE-2022-38512 [MEDIUM] CWE-269 Liferay Portal and Liferay DXP Fails to Check Permissions in Translation Module
Liferay Portal and Liferay DXP Fails to Check Permissions in Translation Module
The Translation module before v2.0.58 from Liferay Portal (v7.4.3.12 through v7.4.3.36), and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.
OSV
Liferay Portal and Liferay DXP Fails to Check Permissions in Translation Module
osv·2022-09-23
CVE-2022-38512 [MEDIUM] Liferay Portal and Liferay DXP Fails to Check Permissions in Translation Module
Liferay Portal and Liferay DXP Fails to Check Permissions in Translation Module
The Translation module before v2.0.58 from Liferay Portal (v7.4.3.12 through v7.4.3.36), and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-22
Published