-
Type:
Bug
-
Status: Closed
-
Priority:
Major
-
Resolution: Fixed
-
Affects Version/s: 6.2 EE GA1 (6.2.10)
-
Fix Version/s: 6.2.X EE
-
Component/s: Core Infrastructure, Security Vulnerability
A local file inclusion vulnerability exists with the portlet rendering functionality in the portal. As a result, a user may be able to access portions of the portal the users does not have permission to access.
See also https://web.liferay.com/group/customer/products/portal/security-vulnerability/lsv-142