The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content pages XLIFF translation file via crafted URL.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dxp | Liferay | 7.4-update_10 (including) | 7.4-update_10 (including) |
Dxp | Liferay | 7.4-update_11 (including) | 7.4-update_11 (including) |
Dxp | Liferay | 7.4-update_12 (including) | 7.4-update_12 (including) |
Dxp | Liferay | 7.4-update_13 (including) | 7.4-update_13 (including) |
Dxp | Liferay | 7.4-update_14 (including) | 7.4-update_14 (including) |
Dxp | Liferay | 7.4-update_15 (including) | 7.4-update_15 (including) |
Dxp | Liferay | 7.4-update_16 (including) | 7.4-update_16 (including) |
Dxp | Liferay | 7.4-update_17 (including) | 7.4-update_17 (including) |
Dxp | Liferay | 7.4-update_18 (including) | 7.4-update_18 (including) |
Dxp | Liferay | 7.4-update_19 (including) | 7.4-update_19 (including) |
Dxp | Liferay | 7.4-update_20 (including) | 7.4-update_20 (including) |
Dxp | Liferay | 7.4-update_21 (including) | 7.4-update_21 (including) |
Dxp | Liferay | 7.4-update_22 (including) | 7.4-update_22 (including) |
Dxp | Liferay | 7.4-update_23 (including) | 7.4-update_23 (including) |
Dxp | Liferay | 7.4-update_24 (including) | 7.4-update_24 (including) |
Dxp | Liferay | 7.4-update_25 (including) | 7.4-update_25 (including) |
Dxp | Liferay | 7.4-update_26 (including) | 7.4-update_26 (including) |
Dxp | Liferay | 7.4-update_27 (including) | 7.4-update_27 (including) |
Dxp | Liferay | 7.4-update_28 (including) | 7.4-update_28 (including) |
Dxp | Liferay | 7.4-update_29 (including) | 7.4-update_29 (including) |
Dxp | Liferay | 7.4-update_3 (including) | 7.4-update_3 (including) |
Dxp | Liferay | 7.4-update_30 (including) | 7.4-update_30 (including) |
Dxp | Liferay | 7.4-update_31 (including) | 7.4-update_31 (including) |
Dxp | Liferay | 7.4-update_32 (including) | 7.4-update_32 (including) |
Dxp | Liferay | 7.4-update_33 (including) | 7.4-update_33 (including) |
Dxp | Liferay | 7.4-update_34 (including) | 7.4-update_34 (including) |
Dxp | Liferay | 7.4-update_35 (including) | 7.4-update_35 (including) |
Dxp | Liferay | 7.4-update_36 (including) | 7.4-update_36 (including) |
Dxp | Liferay | 7.4-update_8 (including) | 7.4-update_8 (including) |
Dxp | Liferay | 7.4-update_9 (including) | 7.4-update_9 (including) |
Liferay_portal | Liferay | 7.4.3.12 (including) | 7.4.3.36 (including) |