Loading HuntDB...

GHSA-5pp7-m8x8-rc82

GitHub Security Advisory

Liferay Portal allows remote attackers to view display page templates via crafted URLs

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, and 7.3 GA through update 35 does not perform an authorization check when users attempt to view a display page template, which allows remote attackers to view display page templates via crafted URLs.

Affected Packages

Maven com.liferay:com.liferay.asset.display.page.service
Affected versions: 0 (fixed in 4.0.55)

Related CVEs

Key Information

GHSA ID
GHSA-5pp7-m8x8-rc82
Published
September 17, 2025 12:31 AM
Last Modified
September 17, 2025 7:14 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
com.liferay:com.liferay.asset.display.page.service
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 18, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.