Total vulnerabilities in the database
The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which allows remote attackers to obtain a WikiNode object via the WikiNodeResource.getSiteWikiNodeByExternalReferenceCode API.
Software | From | Fixed in |
---|---|---|
liferay / digital_experience_platform | 7.4 | 7.4.x |
liferay / liferay_portal | 7.4.1 | 7.4.3.5 |
![]() |
7.4.1 | 7.4.3.5 |