The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 5, does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the page via a site's page administration.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-08-03T18:24:05

Updated: 2024-08-03T23:50:42.915Z

Reserved: 2021-05-20T00:00:00

Link: CVE-2021-33324

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-08-03T19:15:08.690

Modified: 2021-08-11T14:49:04.460

Link: CVE-2021-33324

cve-icon Redhat

No data.