CVE-2024-25148

MEDIUM

Liferay Portal/DXP <7.4.1-SP3, 7.2<FP15 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions the `doAsUserId` URL parameter may get leaked when creating linked content using the WYSIWYG editor and while impersonating a user. This may allow remote authenticated users to impersonate a user after accessing the linked content.

References (1)

Core 1

Scores

CVSS v3 5.4
EPSS 0.0043
EPSS Percentile 62.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (5)
com.liferay.portal/release.dxp.bom 7.2.0 - 7.2.10.fp15Maven
com.liferay.portal/release.portal.bom 7.2.0 - 7.4.2Maven
liferay/digital_experience_platform 7.2 (15 CPE variants)
liferay/dxp 7.3 (3 CPE variants)
liferay/liferay_portal 7.2.0 - 7.4.1
Published Feb 08, 2024
Tracked Since Feb 18, 2026