#VU86597 Improper access control in Liferay Enterprise Portal and Liferay DXP - CVE-2024-25149
Published: February 20, 2024
Liferay Enterprise Portal
Liferay DXP
Liferay
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the affected application does not properly restrict membership of a child site when the "Limit membership to members of the parent site" option is enabled. A remote user can add users who are not a member of the parent site to a child site.