cbcvebase.
CVE-2024-25148
published 2024-02-08

CVE-2024-25148: In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported…

PriorityP347high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.55%
42.3th percentile
In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions the `doAsUserId` URL parameter may get leaked when creating linked content using the WYSIWYG editor and while impersonating a user. This may allow remote authenticated users to impersonate a user after accessing the linked content.

Affected

6 ranges
VendorProductVersion rangeFixed in
liferaydigital_experience_platform
liferaydxp
liferaydxp7.2.10 – 7.2.10-dxp-14
liferaydxp7.3.10 – 7.3.10-dxp-2
liferayliferay_portal7.2.0 – 7.4.1
liferayportal7.2.0 – 7.4.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.