ZeroHour

CVE-2022-41414

CVSS 3.1
5.3 medium
EPSS
<1%p38
Published
()
Modified
Description

An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.

Vendors
liferay
Products
liferay portal
Weakness
CWE-276
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.