CVE-2023-33949
published 2023-05-24CVE-2023-33949: In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.74%
50.7th percentile
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property `company.security.strangers.verify` should be set to true.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | digital_experience_platform | 7.0 – 7.2 | — |
| liferay | dxp | < 7.3.10 | 7.3.10 |
| liferay | liferay_portal | — | — |
| liferay | liferay_portal | 7.0.0 – 7.0.6 | — |
| liferay | liferay_portal | 7.1.0 – 7.1.3 | — |
| liferay | liferay_portal | 7.2.0 – 7.2.1 | — |
| liferay | portal | <= 7.3.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Insecure Default Initialization In Liferay Portal
osv·2023-05-24
CVE-2023-33949 [MEDIUM] Insecure Default Initialization In Liferay Portal
Insecure Default Initialization In Liferay Portal
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property `company.security.strangers.verify` should be set to true.
GHSA
Insecure Default Initialization In Liferay Portal
ghsa·2023-05-24
CVE-2023-33949 [MEDIUM] CWE-1188 Insecure Default Initialization In Liferay Portal
Insecure Default Initialization In Liferay Portal
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property `company.security.strangers.verify` should be set to true.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-24
Published