Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated users to obtain a users full name from the pages title by enumerating user screen names.
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Digital_experience_platform | Liferay | * | 7.2 (excluding) |
Digital_experience_platform | Liferay | 7.2 (including) | 7.2 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_1 (including) | 7.2-fix_pack_1 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_10 (including) | 7.2-fix_pack_10 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_11 (including) | 7.2-fix_pack_11 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_12 (including) | 7.2-fix_pack_12 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_13 (including) | 7.2-fix_pack_13 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_14 (including) | 7.2-fix_pack_14 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_15 (including) | 7.2-fix_pack_15 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_16 (including) | 7.2-fix_pack_16 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_17 (including) | 7.2-fix_pack_17 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_18 (including) | 7.2-fix_pack_18 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_2 (including) | 7.2-fix_pack_2 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_3 (including) | 7.2-fix_pack_3 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_4 (including) | 7.2-fix_pack_4 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_5 (including) | 7.2-fix_pack_5 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_6 (including) | 7.2-fix_pack_6 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_7 (including) | 7.2-fix_pack_7 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_8 (including) | 7.2-fix_pack_8 (including) |
Digital_experience_platform | Liferay | 7.2-fix_pack_9 (including) | 7.2-fix_pack_9 (including) |
Digital_experience_platform | Liferay | 7.2-service_pack_1 (including) | 7.2-service_pack_1 (including) |
Digital_experience_platform | Liferay | 7.2-service_pack_2 (including) | 7.2-service_pack_2 (including) |
Digital_experience_platform | Liferay | 7.2-service_pack_3 (including) | 7.2-service_pack_3 (including) |
Digital_experience_platform | Liferay | 7.2-service_pack_4 (including) | 7.2-service_pack_4 (including) |
Digital_experience_platform | Liferay | 7.2-service_pack_5 (including) | 7.2-service_pack_5 (including) |
Digital_experience_platform | Liferay | 7.2-service_pack_6 (including) | 7.2-service_pack_6 (including) |
Digital_experience_platform | Liferay | 7.3 (including) | 7.3 (including) |
Digital_experience_platform | Liferay | 7.3-fix_pack_1 (including) | 7.3-fix_pack_1 (including) |
Digital_experience_platform | Liferay | 7.3-fix_pack_2 (including) | 7.3-fix_pack_2 (including) |
Digital_experience_platform | Liferay | 7.3-service_pack_1 (including) | 7.3-service_pack_1 (including) |
Digital_experience_platform | Liferay | 7.3-service_pack_3 (including) | 7.3-service_pack_3 (including) |
Liferay_portal | Liferay | * | 7.4.3.4 (excluding) |