CVE-2014-3417 Information
Feb 14, 2021
cve
Description
uPortal before 4.0.13.1 does not properly check the CONFIG permission which allows remote authenticated users to configure portlets by leveraging the SUBSCRIBE permission for a portlet.
Reference
http://www.jasig.org/uportal/download/uportal-4-0-13-1 https://issues.jasig.org/browse/UP-4106
Share on: