Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated users to obtain a user's full name from the page's title by enumerating user screen names.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Liferay

Published: 2024-02-20T08:11:28.312Z

Updated: 2024-08-01T23:36:21.623Z

Reserved: 2024-02-06T10:32:42.567Z

Link: CVE-2024-25150

cve-icon Vulnrichment

Updated: 2024-08-01T23:36:21.623Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-20T08:15:07.290

Modified: 2024-02-20T19:50:53.960

Link: CVE-2024-25150

cve-icon Redhat

No data.