Improper access control in Liferay Enterprise Portal and Liferay DXP - CVE-2024-25149
Published: February 20, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected application does not properly restrict membership of a child site when the "Limit membership to members of the parent site" option is enabled. A remote user can add users who are not a member of the parent site to a child site.
Affected software
Liferay DXP
How to mitigate CVE-2024-25149
Liferay DXP - addressed in versions 7.2 fix pack 15, 7.3 service pack 3