Liferay Portal and Liferay DXP Information Disclosure Vulnerability in the Control Panel
Moderate severity
GitHub Reviewed
Published
Feb 20, 2024
to the GitHub Advisory Database
•
Updated Jul 29, 2025
Description
Published by the National Vulnerability Database
Feb 20, 2024
Published to the GitHub Advisory Database
Feb 20, 2024
Reviewed
Jul 29, 2025
Last updated
Jul 29, 2025
Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions allows remote authenticated users to obtain a user's full name from the page's title by enumerating user screen names.
References