LSV-762: Non-company admins can edit company admins

Fix versions

7.0 Fix Pack Version

None

7.1 Fix Pack Version

20

7.2 Fix Pack Version

9

7.3 Fix Pack Version

None

7.4 Fix Pack Version

None

CVE IDs

CVSS Base Score

CVSS Vector String

Description

Privilege escalation vulnerability in Liferay DXP 7.1 and 7.2 allows remote authenticated users with permission to update/edit users to take over a company administrator user account by editing the company administrator user.

 

Activity

Show:
Fixed
Pinned fields
Click on the next to a field label to start pinning.

Details

Assignee

Reporter

Priority

Zendesk Support

Created September 28, 2020 at 2:20 PM
Updated August 2, 2021 at 12:27 AM
Resolved December 11, 2020 at 1:52 AM