Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-42126
HistoryNov 15, 2022 - 1:15 a.m.

Code injection

2022-11-1501:15:00
PRIOn knowledge base
www.prio-n.com
6
code injection
liferay portal
asset libraries
unauthorized access

4.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.8%

The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 before update 29 does not properly check permissions of asset libraries, which allows remote authenticated users to view asset libraries via the UI.

4.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.8%

Related for PRION:CVE-2022-42126