
We found results for “”
CVE-2023-33949
Date: May 24, 2023
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property "company.security.strangers.verify" should be set to true.
Language: Java
Severity Score
Severity Score
Weakness Type (CWE)
Initialization of a Resource with an Insecure Default
CWE-1188CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | LOW |
Availability (A): | NONE |