CVE-2022-38512

MEDIUM

Liferay Portal/DXP <7.4.3.37 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.

References (2)

Core 2
Core References
Product x_refsource_misc
http://liferay.com

Scores

CVSS v3 6.5
EPSS 0.0022
EPSS Percentile 44.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (4)
com.liferay/com.liferay.translation.web 0 - 2.0.58Maven
com.liferay.portal/release.dxp.bom 7.4.13.u8 - 7.4.13.u37Maven
liferay/dxp 7.4 update_10 (30 CPE variants)
liferay/liferay_portal 7.4.3.12 - 7.4.3.36
Published Sep 22, 2022
Tracked Since Feb 18, 2026