The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 5, does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the page via a site's page administration.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-08-03T18:24:05
Updated: 2024-08-03T23:50:42.915Z
Reserved: 2021-05-20T00:00:00
Link: CVE-2021-33324
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-08-03T19:15:08.690
Modified: 2024-11-21T06:08:41.510
Link: CVE-2021-33324
Redhat
No data.