Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated users to obtain a user's full name from the page's title by enumerating user screen names.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Liferay
Published: 2024-02-20T08:11:28.312Z
Updated: 2024-08-01T23:36:21.623Z
Reserved: 2024-02-06T10:32:42.567Z
Link: CVE-2024-25150
Vulnrichment
Updated: 2024-08-01T23:36:21.623Z
NVD
Status : Awaiting Analysis
Published: 2024-02-20T08:15:07.290
Modified: 2024-02-20T19:50:53.960
Link: CVE-2024-25150
Redhat
No data.