CVE-2021-33333 Information
Jun 07, 2022
cve
Description
The Portal Workflow module in Liferay Portal 7.3.2 and earlier and Liferay DXP 7.0 before fix pack 93 7.1 before fix pack 19 and 7.2 before fix pack 6 does not properly check user permission which allows remote authenticated users to view and delete workflow submissions via crafted URLs.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Reference
https://issues.liferay.com/browse/LPE-17032 https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/id/120747742
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
6.3
Share on: