Details
-
Bug
-
Status: Closed
-
Minor
-
Resolution: Fixed
-
7.0 DE (7.0.10), 7.1 DXP (7.1.10), 7.2 DXP (7.2.10)
-
CVE-2021-33322
-
6.5
-
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
-
96
-
18
-
5
Description
Password reset tokens in Liferay DXP 7.0, 7.1, and 7.2 are not invalidated after users changes their password, which allows remote attackers to change users password via the invalidated password reset token.