Remote Wiki Page Ownership Vulnerability
CVE-2022-45320
6.3MEDIUM
Key Information:
- Vendor
Liferay
- Vendor
- CVE Published:
- 20 February 2024
What is CVE-2022-45320?
A security issue exists in Liferay Portal and Liferay DXP that allows remote authenticated users to gain unauthorized control over wiki pages. This vulnerability enables those users to edit existing wiki pages and change the ownership, which could lead to unauthorized modifications and potential data breaches. Affected versions include earlier releases of Liferay Portal and multiple iterations of Liferay DXP. Immediate action is advisable to mitigate risks associated with this vulnerability.
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved