Lucene search

K
cve[email protected]CVE-2022-38512
HistorySep 22, 2022 - 1:15 a.m.

CVE-2022-38512

2022-09-2201:15:11
CWE-862
web.nvd.nist.gov
28
4
translation module
liferay portal
liferay dxp
cve-2022-38512
security vulnerability
xliff
unauthorized access

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

52.5%

The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not check permissions before allowing a user to export a web content for translation, allowing attackers to download a web content page’s XLIFF translation file via crafted URL.

Affected configurations

NVD
Node
liferaydxpMatch7.4update_10
OR
liferaydxpMatch7.4update_11
OR
liferaydxpMatch7.4update_12
OR
liferaydxpMatch7.4update_13
OR
liferaydxpMatch7.4update_14
OR
liferaydxpMatch7.4update_15
OR
liferaydxpMatch7.4update_16
OR
liferaydxpMatch7.4update_17
OR
liferaydxpMatch7.4update_18
OR
liferaydxpMatch7.4update_19
OR
liferaydxpMatch7.4update_20
OR
liferaydxpMatch7.4update_21
OR
liferaydxpMatch7.4update_22
OR
liferaydxpMatch7.4update_23
OR
liferaydxpMatch7.4update_24
OR
liferaydxpMatch7.4update_25
OR
liferaydxpMatch7.4update_26
OR
liferaydxpMatch7.4update_27
OR
liferaydxpMatch7.4update_28
OR
liferaydxpMatch7.4update_29
OR
liferaydxpMatch7.4update_3
OR
liferaydxpMatch7.4update_30
OR
liferaydxpMatch7.4update_31
OR
liferaydxpMatch7.4update_32
OR
liferaydxpMatch7.4update_33
OR
liferaydxpMatch7.4update_34
OR
liferaydxpMatch7.4update_35
OR
liferaydxpMatch7.4update_36
OR
liferaydxpMatch7.4update_8
OR
liferaydxpMatch7.4update_9
OR
liferayliferay_portalRange7.4.3.127.4.3.36

Social References

More

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

52.5%

Related for CVE-2022-38512