CVE-2022-45320Improper Access Control in Digital Experience Platform

Severity
6.3MEDIUMNVD
EPSS
0.4%
top 41.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20

Description

Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.4

Affected Packages2 packages

🔴Vulnerability Details

3
CVEList
CVE-2022-45320: Liferay Portal before 72024-02-20
GHSA
Privilege escalation in Liferay Portal2024-02-20
OSV
Privilege escalation in Liferay Portal2024-02-20
CVE-2022-45320 — Improper Access Control | cvebase