Looking for the vulnerability index of Invicti's legacy products?
Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2021-33324) - Vulnerability Database

Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2021-33324)

Description

The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 5, does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the page via a site's page administration.

References

Related Vulnerabilities