Remote Wiki Page Ownership Vulnerability
CVE-2022-45320

6.3MEDIUM

Key Information:

Vendor

Liferay

Vendor
CVE Published:
20 February 2024

What is CVE-2022-45320?

A security issue exists in Liferay Portal and Liferay DXP that allows remote authenticated users to gain unauthorized control over wiki pages. This vulnerability enables those users to edit existing wiki pages and change the ownership, which could lead to unauthorized modifications and potential data breaches. Affected versions include earlier releases of Liferay Portal and multiple iterations of Liferay DXP. Immediate action is advisable to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-45320 : Remote Wiki Page Ownership Vulnerability