Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2024-25150

Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated users to obtain a user's full name from the page's title by enumerating user screen names.

  • Published: Feb 20, 2024
  • Updated: May 4, 2025
  • CVE: CVE-2024-25150
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

No CWE or OWASP classifications available.

Software From Fixed in
liferay / digital_experience_platform 7.2 7.2.x
liferay / digital_experience_platform 7.2-fix_pack_1 7.2-fix_pack_1.x
liferay / digital_experience_platform 7.2-fix_pack_2 7.2-fix_pack_2.x
liferay / digital_experience_platform 7.2-fix_pack_3 7.2-fix_pack_3.x
liferay / digital_experience_platform 7.2-fix_pack_5 7.2-fix_pack_5.x
liferay / digital_experience_platform 7.2-fix_pack_4 7.2-fix_pack_4.x
liferay / digital_experience_platform 7.2-fix_pack_6 7.2-fix_pack_6.x
liferay / digital_experience_platform 7.2-fix_pack_7 7.2-fix_pack_7.x
liferay / digital_experience_platform 7.2-fix_pack_8 7.2-fix_pack_8.x
liferay / digital_experience_platform 7.2-fix_pack_9 7.2-fix_pack_9.x
liferay / digital_experience_platform 7.2-fix_pack_11 7.2-fix_pack_11.x
liferay / digital_experience_platform 7.2-fix_pack_12 7.2-fix_pack_12.x
liferay / digital_experience_platform 7.2-fix_pack_13 7.2-fix_pack_13.x
liferay / digital_experience_platform 7.2-fix_pack_14 7.2-fix_pack_14.x
liferay / digital_experience_platform 7.2-fix_pack_15 7.2-fix_pack_15.x
liferay / digital_experience_platform 7.2-fix_pack_16 7.2-fix_pack_16.x
liferay / digital_experience_platform 7.3 7.3.x
liferay / digital_experience_platform 7.3-fix_pack_1 7.3-fix_pack_1.x
liferay / liferay_portal - 7.4.3.4
liferay / digital_experience_platform 7.2-fix_pack_10 7.2-fix_pack_10.x
liferay / digital_experience_platform 7.2-fix_pack_17 7.2-fix_pack_17.x
liferay / digital_experience_platform 7.2-fix_pack_18 7.2-fix_pack_18.x
liferay / digital_experience_platform - 7.2
liferay / digital_experience_platform 7.3-service_pack_3 7.3-service_pack_3.x
liferay / digital_experience_platform 7.3-fix_pack_2 7.3-fix_pack_2.x
liferay / digital_experience_platform 7.3-service_pack_1 7.3-service_pack_1.x
liferay / digital_experience_platform 7.2-service_pack_2 7.2-service_pack_2.x
liferay / digital_experience_platform 7.2-service_pack_3 7.2-service_pack_3.x
liferay / digital_experience_platform 7.2-service_pack_4 7.2-service_pack_4.x
liferay / digital_experience_platform 7.2-service_pack_5 7.2-service_pack_5.x
liferay / digital_experience_platform 7.2-service_pack_6 7.2-service_pack_6.x
liferay / digital_experience_platform 7.2-service_pack_1 7.2-service_pack_1.x