Details
-
Bug
-
Status: Closed
-
Minor
-
Resolution: Fixed
-
7.0 DE (7.0.10), 7.1 DXP (7.1.10), 7.2 DXP (7.2.10)
-
CVE-2021-33325
-
4.9
-
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
-
93
-
19
-
7
Description
In Liferay DXP 7.0, 7.1 and 7.2, user's passwords are stored in the database if workflow is enabled for new users. This allows attackers with access to the database to obtain the user's unencrypted password.