CVE-2022-45320
published 2024-02-20CVE-2022-45320: Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become…
PriorityP334medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.48%
38.3th percentile
Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | digital_experience_platform | < 7.2 | 7.2 |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | digital_experience_platform | — | — |
| liferay | liferay_portal | < 7.4.3.16 | 7.4.3.16 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Privilege escalation in Liferay Portal
ghsa·2024-02-20
CVE-2022-45320 [MEDIUM] CWE-284 Privilege escalation in Liferay Portal
Privilege escalation in Liferay Portal
Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page.
OSV
Privilege escalation in Liferay Portal
osv·2024-02-20
CVE-2022-45320 [MEDIUM] Privilege escalation in Liferay Portal
Privilege escalation in Liferay Portal
Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-20
Published