-
Type:
Bug
-
Status: Closed
-
Priority:
Minor
-
Resolution: Fixed
-
Affects Version/s: 7.0 DE (7.0.10), 7.1 DXP (7.1.10)
-
Component/s: Application Security > Permissions, Security Vulnerability
-
7.0 Fix Pack Version:59
Portlet configuration in Liferay DXP 7.0 does not properly verify permission which may lead to attackers changing portlet configuration settings and gaining access to sensitive information via crafted URL.