CVE-2022-42128 Information
Nov 16, 2022
cve
Description
The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4 and Liferay DXP 7.4 GA does not properly check permissions which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API.
Reference
https://issues.liferay.com/browse/LPE-17595 http://liferay.com https://portal.liferay.dev/learn/security/known-vulnerabilities/-/asset_publisher/HbL5mxmVrnXW/content/cve-2022-42128
Share on: