An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers to enumerate usernames, site names, and pages.
2022-10-07T18:15:22.640
2024-11-21T07:23:10.997
Modified
CVSSv3.1: 5.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | liferay | liferay_portal | ≤ 7.4.2 | Yes |