Description
The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.
References (2)
Core 2
Core References
Product x_refsource_misc
http://liferay.com
Release Notes, Vendor Advisory x_refsource_misc
https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-38512
Scores
CVSS v3
6.5
EPSS
0.0022
EPSS Percentile
44.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (4)
com.liferay/com.liferay.translation.web
0 - 2.0.58Maven
com.liferay.portal/release.dxp.bom
7.4.13.u8 - 7.4.13.u37Maven
liferay/dxp
7.4 update_10 (30 CPE variants)
liferay/liferay_portal
7.4.3.12 - 7.4.3.36
Published
Sep 22, 2022
Tracked Since
Feb 18, 2026