6.5

CVE-2022-38512

The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page's XLIFF translation file via crafted URL.

Data is provided by the National Vulnerability Database (NVD)
LiferayDxp Version7.4 Updateupdate_10
LiferayDxp Version7.4 Updateupdate_11
LiferayDxp Version7.4 Updateupdate_12
LiferayDxp Version7.4 Updateupdate_13
LiferayDxp Version7.4 Updateupdate_14
LiferayDxp Version7.4 Updateupdate_15
LiferayDxp Version7.4 Updateupdate_16
LiferayDxp Version7.4 Updateupdate_17
LiferayDxp Version7.4 Updateupdate_18
LiferayDxp Version7.4 Updateupdate_19
LiferayDxp Version7.4 Updateupdate_20
LiferayDxp Version7.4 Updateupdate_21
LiferayDxp Version7.4 Updateupdate_22
LiferayDxp Version7.4 Updateupdate_23
LiferayDxp Version7.4 Updateupdate_24
LiferayDxp Version7.4 Updateupdate_25
LiferayDxp Version7.4 Updateupdate_26
LiferayDxp Version7.4 Updateupdate_27
LiferayDxp Version7.4 Updateupdate_28
LiferayDxp Version7.4 Updateupdate_29
LiferayDxp Version7.4 Updateupdate_3
LiferayDxp Version7.4 Updateupdate_30
LiferayDxp Version7.4 Updateupdate_31
LiferayDxp Version7.4 Updateupdate_32
LiferayDxp Version7.4 Updateupdate_33
LiferayDxp Version7.4 Updateupdate_34
LiferayDxp Version7.4 Updateupdate_35
LiferayDxp Version7.4 Updateupdate_36
LiferayDxp Version7.4 Updateupdate_8
LiferayDxp Version7.4 Updateupdate_9
LiferayLiferay Portal Version >= 7.4.3.12 <= 7.4.3.36
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.22% 0.447
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.