Vulnerabilities > CVE-2024-25604 - Incorrect Authorization vulnerability in Liferay Digital Experience Platform and Liferay Portal

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
liferay
CWE-863

Summary

Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions does not properly check user permissions, which allows remote authenticated users with the VIEW user permission to edit their own permission via the User and Organizations section of the Control Panel.

Vulnerable Configurations

Part Description Count
Application
Liferay
421

Common Weakness Enumeration (CWE)