MEDIUM
Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page
Published Feb 20, 2024
6.3
MEDIUMCVSS 3.1
EPSS 0.48%
Description
Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page.
Affected products
No data.
OR
- < 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.2
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.3
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- 7.4
- < 7.4.3.16
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://github.com/advisories/GHSA-mc8m-4r3w-q2hw Advisory
- https://github.com/liferay/liferay-portal/releases/tag/7.4.3.16-ga16
- https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2022-45320 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-45320
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 20, 2024
Updated Mar 28, 2025
Reserved Nov 14, 2022
Link CVE-2022-45320
CISA Vulnrichment
GHSA-MC8M-4R3W-Q2HW Updated Feb 20, 2024