Security Advisory

CVE-2021-33335

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-08-03 21:03:38
Last updated 2024-08-03 23:50:42
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Privilege escalation vulnerability in Liferay Portal 7.0.3 through 7.3.4, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 9 allows remote authenticated users with permission to update/edit users to take over a company administrator user account by editing the company administrator user.